Live data from Hacker News

Secret Code Found in Juniper's Firewalls Shows Risk of Government Backdoors

wired.com

61–70 of 121 posts

Re: Secret Code Found in Juniper's Firewalls Shows Risk of Government Backdoors

#61
"I am shocked—shocked—to find that gambling is going on in here!"

--from "Casablanca"

I'd be shocked to learn that there are no back doors in routing equipment. Having that kind of control is just too appealing to the most powerful players -- the NSA, China, perhaps Russia.

One hopes that people who care about the privacy of their communications are not relying on the routers for encryption. I would encrypt end-to-end. Even if the spooks are capturing the data, let them work for their cleartext.

Of course, we have to use algorithms that aren't compromised, either.

Annoying and disturbing. And they can't claim it's needed to stop terrorism, either. The U.S. anti-terrorism apparatus didn't spot an obviously dangerous couple in San Bernardino, even after one of them posted jihadist goals on her stream. They didn't stop the Tsarnaev brothers from bombing the Boston Marathon even after the Russians phoned to warn us about them. Idiots.

Re: Secret Code Found in Juniper's Firewalls Shows Risk of Government Backdoors

#62
post #11

Earlier quoted context omitted.

Yeah, because illegitimate / spoofed certificates will never happen...

With certificate transparency, at least we'll know about it - afterwards, at least.

Well, afterwards, if the attack stops (software does not need to stop) in a timeframe short enough for your computer to no clear its history.

Re: Secret Code Found in Juniper's Firewalls Shows Risk of Government Backdoors

#63
post #32

Don't gouvernements can check the source code? like for Windows?

Well, at the specific case of Windows, Microsoft ships something they say is the source code of it. But nobody is allowed to compile it, and can not do so in practice, because they don't ship the building environment.

Re: Secret Code Found in Juniper's Firewalls Shows Risk of Government Backdoors

#64
post #32

Don't gouvernements can check the source code? like for Windows?

It's an interesting thought. If they checked and spotted this would they report it to defend against the attacker that injected it, or would they just pocket the master password and use it themselves?

Maybe both: They found a second backdoor, reported one and kept the other. This makes them trustworthy in the eyes of Juniper, while still netting them a backdoor.

Re: Secret Code Found in Juniper's Firewalls Shows Risk of Government Backdoors

#65
I think these is a good example for people that complained about OpenBSD refusing to use cloud servers for their infrastructure. Point being security at this level shouldn't be taken lightly. Juniper must have a ton of security measures in place and they end up with this.

Re: Secret Code Found in Juniper's Firewalls Shows Risk of Government Backdoors

#66

"I am shocked—shocked—to find that gambling is going on in here!" --from "Casablanca" I'd be shocked to learn that there are no back doors in routing equipment. Having that kind of control is just too appealing to the most powerful players -- the NSA, China, perhaps Russia. One hopes that people who care about the privacy of their communications are not relying on the routers for encryption. I would encrypt end-to-en…

Wish I could up vote this more. The government has nearly nothing to show for all their surveillance and yet they keep asking for more.

Re: Secret Code Found in Juniper's Firewalls Shows Risk of Government Backdoors

#67
post #6

It's sad but events like this one make me turn away from Internet. I started using Signal because I don't want people seeing the messages I post. But in the end it's only trust that makes me think Signal is safe to use. A lot of people also trusted Juniper. But that trust is gone. And not only for Juniper. What about other brands? We don't know.

It's sad but comments like this made me turn away from language as a reliable means of communication. I used to believe anything I'd read. But, having become aware of trolls and worse, those days are gone. Not only English, but Japanese and who knows which other languages are untrustworthy.

I'm not sure what you are trying to communicate.

Trust is something delicate which works best by using face to face communication.

So it's ok not to trust everything you read.

But this story is about private communication not being as private as thought.

Re: Secret Code Found in Juniper's Firewalls Shows Risk of Government Backdoors

#68
Juniper is using Dual EC....are you kidding me? Now I have zero doubt this is Juniper's fault because of its cooperation with NSA to keep backdoors in its systems.

If I remember correctly even tptacek was claiming initially that "Dual EC is not so bad...not that many companies use it anyway, because they would be stupid to use a 1000x slower algorithm". Yeah, except some of the biggest networking equipment makers in the world who do use it, and who sell products to many other small and large companies, too. Quite a bit of an attack surface for the NSA.

The point was always that Dual_EC should've never become a NIST standard, no matter how "bad it was and that probably nobody would use it anyway". It was made a standard for a reason by the NSA, to convince at least some of the big companies to use it. And they succeeded in that.

We can only hope that the good people who work in standard bodies will never allow something like that to happen again, because in the end backdoors always end up being used for "evil", whether by the initial creators or by someone else who finds them later.

Re: Secret Code Found in Juniper's Firewalls Shows Risk of Government Backdoors

#69

"I am shocked—shocked—to find that gambling is going on in here!" --from "Casablanca" I'd be shocked to learn that there are no back doors in routing equipment. Having that kind of control is just too appealing to the most powerful players -- the NSA, China, perhaps Russia. One hopes that people who care about the privacy of their communications are not relying on the routers for encryption. I would encrypt end-to-en…

I read from a reliable source I cannot immediately recall that she in fact did not post anything jihadist or even inflammatory on any social media account of hers.

are you repeating a convenient falsehood or am I? in other words -- do you have a source that verified she in fact posted jihadist anything, anywhere?

Re: Secret Code Found in Juniper's Firewalls Shows Risk of Government Backdoors

#70

Earlier quoted context omitted.

I was thinking the same thing. Honeymoon's over? What honeymoon? There never was a honeymoon!

Objectively, perhaps not. (I suppose I remember the early days of the Internet when it wasn't that popular.) My gist is that our implicit trust in the system/infrastructure we rely on is undermined by this sort of revelation. And yet, as a whole, we de facto continue to trust in opaque entities that provide valuable yet likely compromised services because it is convenient.

This should not be a revelation though. Granted, back when the Internet wasn't so popular, the risk for people like you and me, or for small companies, was relatively low. Partly because the value of Internet-accessible information was relatively low, too -- twenty years ago, if I bought a backdoored home router, all the Evil Guys would get access to would be really bad code snippets and a few folders of porn pics.

But the fact that people with access to your infrastructure also had access to your data was more or less well known ever since "the beginning", and it's also why internetworks other than the Internet were a thing for a long time.

> And yet, as a whole, we de facto continue to trust in opaque entities that provide valuable yet likely compromised services because it is convenient.

Don't forget the scarcity of alternatives though. It takes a lot of money to come up with a credible alternative to Juniper and Cisco. Siphoning personal data is what sells nowadays, not protecting it.

Post reply on HN