Live data from Hacker News

Secret Code Found in Juniper's Firewalls Shows Risk of Government Backdoors

wired.com

41–50 of 121 posts

Re: Secret Code Found in Juniper's Firewalls Shows Risk of Government Backdoors

#41
post #25

Earlier quoted context omitted.

It would appear that the "party of reasonable size" here is China or Russia, not a corporation.

Can you please explain how you reached that conclusion? What made you exclude US and UK?

Parent is probably taking the CNN article at face value.

Re: Secret Code Found in Juniper's Firewalls Shows Risk of Government Backdoors

#42
post #37
post #34

Earlier quoted context omitted.

Signal is open source. But you have to trust the OS it runs on...

And even if you trust the OS, you have no idea what is going on on the phone's baseband processor: https://en.m.wikipedia.org/wiki/Baseband_processor One has to assume that all are back-doored. Mobile phones are inherently not trustable. Same goes for all major firewall vendors. If you going to hack one of them as a nation state, then you're going to do all of them.

There is at least one project that seeks to mitigate the threat posed by baseband processors having DMA, Neo900: http://neo900.org/faq#privacy

Re: Secret Code Found in Juniper's Firewalls Shows Risk of Government Backdoors

#43
post #6

It's sad but events like this one make me turn away from Internet. I started using Signal because I don't want people seeing the messages I post. But in the end it's only trust that makes me think Signal is safe to use. A lot of people also trusted Juniper. But that trust is gone. And not only for Juniper. What about other brands? We don't know.

It's sad but comments like this made me turn away from language as a reliable means of communication. I used to believe anything I'd read. But, having become aware of trolls and worse, those days are gone. Not only English, but Japanese and who knows which other languages are untrustworthy.

Re: Secret Code Found in Juniper's Firewalls Shows Risk of Government Backdoors

#44
This also highlights why it would be better to use opensource firewalls such as Openbsd instead of proprietary ones!

If you care about your security then you need to be able to inspect the code that protects your assets.

Distributed open source firewall vs propritary firewall with backdoors.

Re: Secret Code Found in Juniper's Firewalls Shows Risk of Government Backdoors

#45
post #26

The honeymoon is over. The Internet is now a hostile environment. We cannot assume good conduct from any party of reasonable size and should assume deception from anything that isn't fully open source and vocal about it. It sucks to assume the worst...

That has always been the case. It's always been the case that if your adversary is a well funded government you need very careful security. We knew this from Echelon in the 1980s.

I was thinking the same thing. Honeymoon's over? What honeymoon? There never was a honeymoon!

Re: Secret Code Found in Juniper's Firewalls Shows Risk of Government Backdoors

#46

I'm confused. Are these accidental vulnerabilities or deliberate backdoors? If deliberate, why is there speculation about who might have installed this "secret code"? Do they have version control? Is there a specific human attached to the relevant commits? Serious question.

This is a very important point. Are the backdoor(s) traceable to a specific event or individual? How far up the company hierarchy does the rot go? Whatever the answer, it is insufficient. We are relying on hardware and software that is opaque at the network level, and therefore open to this sort of manipulation.

Re: Secret Code Found in Juniper's Firewalls Shows Risk of Government Backdoors

#47
post #44

This also highlights why it would be better to use opensource firewalls such as Openbsd instead of proprietary ones! If you care about your security then you need to be able to inspect the code that protects your assets. Distributed open source firewall vs propritary firewall with backdoors.

Of course the idea that open source software in general, and firewalls in specific are better than closed source ones relies on people actually having the skills and time necessary to conduct a decent audit.

Some of the very large security bugs found in open source software which were present in that code for years, indicate that this is not commonly done.

And that was just bugs as opposed to actual backdoors which would likely be harder to find if inserted competently.

So whilst in theory you are correct, I'm not so sure you are in practice.

Re: Secret Code Found in Juniper's Firewalls Shows Risk of Government Backdoors

#48
post #44

This also highlights why it would be better to use opensource firewalls such as Openbsd instead of proprietary ones! If you care about your security then you need to be able to inspect the code that protects your assets. Distributed open source firewall vs propritary firewall with backdoors.

Given that this was hidden even from the organization that was in control of the codebase, it's not clear that open source on its own is a real solution. This made it through whatever initial review processes Juniper has, and was only caught by an "internal code review" performed after the fact - an exercise only infrequently conducted on most open source projects.

Given enough eyeballs backdoors can be easy to spot in source code, but eyeballs aren't an unlimited resource. In addition to open sourcing your software, the community that cares about the project needs enough funding or institutional support to actually review the code in question.

Re: Secret Code Found in Juniper's Firewalls Shows Risk of Government Backdoors

#49

I'm confused. Are these accidental vulnerabilities or deliberate backdoors? If deliberate, why is there speculation about who might have installed this "secret code"? Do they have version control? Is there a specific human attached to the relevant commits? Serious question.

> If deliberate, why is there speculation about who might have installed this "secret code"?

Would you take whatever your VCS claims as face value in this case? I wouldn't, which makes answering this very difficult, so I think it is to be expected that they don't have an answer yet.

Re: Secret Code Found in Juniper's Firewalls Shows Risk of Government Backdoors

#50
post #39

I like CNN's take on the story: http://edition.cnn.com/2015/12/18/politics/juniper-networks-... Obviously it must be either Russia or China - NSA couldn't possibly be responsible ;)

It can't be NSA agents who caught intercepting network gear from Cisco Systems as it was being shipped to a customer (as revealed by snowden) it is highly unlikely they infected juniper networks as well.

To play devil's advocate, it is a big leap going from backdooring a specific device sent to a specific person you may by monitoring, to backdooring every one of those devices. Not that I would put it past NSA, though.
Post reply on HN