Live data from Hacker News

Secret Code Found in Juniper's Firewalls Shows Risk of Government Backdoors

wired.com

91–100 of 121 posts

Re: Secret Code Found in Juniper's Firewalls Shows Risk of Government Backdoors

#91
post #71

Just a quick note that 'lawnchair_larry has me dead to rights on this one. I conceded awhile ago that Dual EC was a crypto backdoor (before BULLRUN and the antics that were uncovered with RSA and with the European standards, I had suggested, as some other crypto people had, that Dual EC was too hamfisted and obvious to be a crypto backdoor). But I've maintained since then that virtually nobody uses Dual EC, so its im…

Could someone provide background on the the Dual EC issue, and why this announcement is probably more important for the Dual EC implications than for Juniper's backdoor, as tptacek says below?

While I wish I was an uber-crypto-nerd, unfortunately I only have time to be an occasional crypto geek.

EDIT: Here's a start, from another front page HN article: "Dual-EC was an NSA effort to introduce a backdoored random number generator (RNG) that, given knowledge of a secret key, allowed an attacker to observe output from the RNG and then predict its future output."

Re: Secret Code Found in Juniper's Firewalls Shows Risk of Government Backdoors

#92
post #87

Earlier quoted context omitted.

You are right. The FBI has corrected the report of her Facebook warnings that was floating around the news networks. Marquez (the Muslim convert who sold them the guns), however, did post something on his verified Facebook account a month before the attack.[1] And Malik (the wife) did apparently post something on Facebook minutes before the attack. Do you disagree with my overall point, that the U.S. law enforcement…

Surveillance is simply a useful scapegoat it's actually fairly useless. The problem is if there are any read flags that get 24/7 monitoring then having several people flip them will quickly destroy the system. Let's say they vent in private conversation well that's legal, they then buy some guns and ammo. Well again that's legal. Then one day they go out and shoot people, well sorry we can't afford to have a swat tea…

I would disagree that surveillance is "fairly useless". Obviously, there are times when keeping a watch on potentially dangerous people is going to pay off. How many times, I can't say.

The problems begin when we have a process-bound bureaucracy rather than a group of smart people, each acting on hunches and excellent information. Bureaucracies can be composed of smart people yet act stupidly.

Also, there are political mandates that certain minorities not be singled out, e.g. the Muslims. Thus, the fact that the three involved in San Bernardino were Muslims did not come into play until well after the shooting. The initial news articles I saw didn't even mention their ethnicities and religious affiliations; even the conservative Wall Street Journal only mentioned it at the very end, and the fact that Marquez was a recent convert to Islam didn't come out until recently.

Re: Secret Code Found in Juniper's Firewalls Shows Risk of Government Backdoors

#93

I'm confused. Are these accidental vulnerabilities or deliberate backdoors? If deliberate, why is there speculation about who might have installed this "secret code"? Do they have version control? Is there a specific human attached to the relevant commits? Serious question.

I wonder the same thing, but with enough resources, there are many ways to attack version control. For example, probably there are exploits in the VCS system and in the database that underlies it, they could steal a developer's credentials or hack his/her account otherwise, attack the compiler ...

Think of the value of all the data in the world that Juniper firewalls protect. Of course every actor that can afford to will invest the resources to introduce back doors. As an example, the NSA had ~30,000 employees and a ~$10 billion budget as of a few years ago; they can afford to do it.

For me, the real question is, how does Juniper address the fact that they are such a target? Do they take adequate security measures for the situation (which would be very expensive)? Just take standard security measures, which very likely would be inadequte, so they can escape liability? How does any such organization deal with it?: Google, Microsoft, Apple, Apache, Linux, etc.

Re: Secret Code Found in Juniper's Firewalls Shows Risk of Government Backdoors

#94
post #71

Just a quick note that 'lawnchair_larry has me dead to rights on this one. I conceded awhile ago that Dual EC was a crypto backdoor (before BULLRUN and the antics that were uncovered with RSA and with the European standards, I had suggested, as some other crypto people had, that Dual EC was too hamfisted and obvious to be a crypto backdoor). But I've maintained since then that virtually nobody uses Dual EC, so its im…

> This backdoor appears to swap out the public key, which is something NSA has no interest in doing.

While they wouldn't need to swap it out (since they can unlock standard Dual EC), that doesn't mean they wouldn't.

Assuming 1) that Dual EC was used here and 2) was inserted surreptitiously in a way that has a nonnegligible chance of discovery, it would make sense to rekey it since failing to do so would strongly attribute the attack to NSA (or someone willing to give up the passive backdoor opportunity in order to pin it on NSA).

The only case for NSA where using the old key would be best is if the use of standards-based Dual EC would pass scrutiny but a modified one would not. This depends on the details.

If switching Juniper to Dual EC required only calling a different function in Juniper's existing crypto library and/or detection was unlikely, standard Dual EC might be best. If the compromise added a full Dual EC implementation, then changing the constants is good (different magic constants don't significantly increase risk of detection for the large inserted code blob while significantly decreasing the risk of attribution).

Re: Secret Code Found in Juniper's Firewalls Shows Risk of Government Backdoors

#95
post #71

Just a quick note that 'lawnchair_larry has me dead to rights on this one. I conceded awhile ago that Dual EC was a crypto backdoor (before BULLRUN and the antics that were uncovered with RSA and with the European standards, I had suggested, as some other crypto people had, that Dual EC was too hamfisted and obvious to be a crypto backdoor). But I've maintained since then that virtually nobody uses Dual EC, so its im…

Could someone provide background on the the Dual EC issue, and why this announcement is probably more important for the Dual EC implications than for Juniper's backdoor, as tptacek says below? While I wish I was an uber-crypto-nerd, unfortunately I only have time to be an occasional crypto geek. EDIT: Here's a start, from another front page HN article: "Dual-EC was an NSA effort to introduce a backdoored random numbe…

Basically, Dual EC is never something you'll choose willingly, given alternatives (it's quite slow and has had a slight bias demonstrated). So no one* did in practice. This made the backdoor almost a non-issue (so no heartbleed-like panic to patch, etc.).

However, having it in the standard (since removed) is perfect for fallback-like attacks or surreptitious changes (in the best case, your target has already implemented and deployed your exploit code and all you have to do is throw the switch to enable it!). That's what this is demonstrating (though some of the details are still speculative).

* Exception being those paid or required to do so by NSA.

Re: Secret Code Found in Juniper's Firewalls Shows Risk of Government Backdoors

#96
post #87

Earlier quoted context omitted.

Surveillance is simply a useful scapegoat it's actually fairly useless. The problem is if there are any read flags that get 24/7 monitoring then having several people flip them will quickly destroy the system. Let's say they vent in private conversation well that's legal, they then buy some guns and ammo. Well again that's legal. Then one day they go out and shoot people, well sorry we can't afford to have a swat tea…

I would disagree that surveillance is "fairly useless". Obviously, there are times when keeping a watch on potentially dangerous people is going to pay off. How many times, I can't say. The problems begin when we have a process-bound bureaucracy rather than a group of smart people, each acting on hunches and excellent information. Bureaucracies can be composed of smart people yet act stupidly. Also, there are politic…

In fiction hunches work well, in the real world there far less valuable.

In terms of mass shootings Muslims are far from the most common profile. Seung-Hui Cho aged 23 for example killed 32 people and wounded 17 in VT on April 16, 2007. Jeffrey Weise, a 16-year-old killed 10 in Red Lake, Minnesota. 21 died at Columbine.

Go though: http://timelines.latimes.com/deadliest-shooting-rampages/ they don't really fit just 1 or 2 profiles.

Re: Secret Code Found in Juniper's Firewalls Shows Risk of Government Backdoors

#97
post #71

Just a quick note that 'lawnchair_larry has me dead to rights on this one. I conceded awhile ago that Dual EC was a crypto backdoor (before BULLRUN and the antics that were uncovered with RSA and with the European standards, I had suggested, as some other crypto people had, that Dual EC was too hamfisted and obvious to be a crypto backdoor). But I've maintained since then that virtually nobody uses Dual EC, so its im…

> This backdoor appears to swap out the public key, which is something NSA has no interest in doing. While they wouldn't need to swap it out (since they can unlock standard Dual EC), that doesn't mean they wouldn't. Assuming 1) that Dual EC was used here and 2) was inserted surreptitiously in a way that has a nonnegligible chance of discovery, it would make sense to rekey it since failing to do so would strongly attr…

No. It is vitally important for NSA not to call attention to their crypto backdoor --- remember, this was inserted in 2012 --- and external tampering with the PKRNG in a VPN device is a smoking gun that Dual_EC is not a benign standard (still a plausible claim in 2012), but rather a surreptitious key escrow mechanism.

No. It is not at all plausible that NSA backdoored ScreenOS in 2012 in order to rekey their backdoor.

Re: Secret Code Found in Juniper's Firewalls Shows Risk of Government Backdoors

#98

Earlier quoted context omitted.

"Instead of using the NIST recommended curve points [ScreenOS] uses self-generated basis points..." [0] The way I read this statement is that each device generates its own set of points. If this is the case, I don't see how it would work as a crypto backdoor. If by "self-generated" they mean generated by Juniper once, well, thats fishy. [0] http://kb.juniper.net/InfoCenter/index?page=content&id=KB282... Edited to add…

Instead of using the NIST recommended curve points it uses self-generated basis points and then takes the output as an input to FIPS/ANSI X.9.31 PRNG, which is the random number generator used in ScreenOS cryptographic operations." Looks like they feed the output through a standard CPRNG. Assuming it's true, that pretty much breaks the DUAL_EC attack because you can't use the output of the final CPRNG to recover the…

I wonder if that's going to be demonstrated to be a true statement, and further whether the tampering Juniper discovered will have disabled that second step.

Re: Secret Code Found in Juniper's Firewalls Shows Risk of Government Backdoors

#99
post #97

Earlier quoted context omitted.

> This backdoor appears to swap out the public key, which is something NSA has no interest in doing. While they wouldn't need to swap it out (since they can unlock standard Dual EC), that doesn't mean they wouldn't. Assuming 1) that Dual EC was used here and 2) was inserted surreptitiously in a way that has a nonnegligible chance of discovery, it would make sense to rekey it since failing to do so would strongly attr…

No. It is vitally important for NSA not to call attention to their crypto backdoor --- remember, this was inserted in 2012 --- and external tampering with the PKRNG in a VPN device is a smoking gun that Dual_EC is not a benign standard (still a plausible claim in 2012), but rather a surreptitious key escrow mechanism. No. It is not at all plausible that NSA backdoored ScreenOS in 2012 in order to rekey their backdoor…

The backdoor possibility was known in 2007 and the standard included a way to set your own constants (which no one used, true, but just because it was true for Dual EC in general).

I disagree that following the standard on that point and creating your own would be a smoking gun that the standard is malicious. Rather, it could be a smoking gun that this implementation was. If the tampering would likely be detected anyway, I'd argue it's better to avoid attribution.

Re: Secret Code Found in Juniper's Firewalls Shows Risk of Government Backdoors

#100
post #74
post #69

Earlier quoted context omitted.

I read from a reliable source I cannot immediately recall that she in fact did not post anything jihadist or even inflammatory on any social media account of hers. are you repeating a convenient falsehood or am I? in other words -- do you have a source that verified she in fact posted jihadist anything, anywhere?

Excellent point. The whole episode is very instructive. On Sunday the New York Times quoted "law enforcement sources" as saying that she had made postings on her stream. The story got a huge amount of coverage and even came up during Tuesday's Republican debate. On Wednesday, FBI Director Comey described the reporting as "grabled" and clarified that no, it was just private messages -- and the Times (and others) rewro…

I wish we had something that tracked news articles and noted when they changed without either an inline note about the change or an update at the end. It would be like the snopes of news journalism, and we could get some really interesting statistics from that with regard to the journalistic integrity of different sources. There's a large population of people that could do with some good evidence to force them to be more critical of certain news sources.
Post reply on HN