Live data from Hacker News

Secret Code Found in Juniper's Firewalls Shows Risk of Government Backdoors

wired.com

111–120 of 121 posts

Re: Secret Code Found in Juniper's Firewalls Shows Risk of Government Backdoors

#111

Earlier quoted context omitted.

I was thinking the same thing. Honeymoon's over? What honeymoon? There never was a honeymoon!

Objectively, perhaps not. (I suppose I remember the early days of the Internet when it wasn't that popular.) My gist is that our implicit trust in the system/infrastructure we rely on is undermined by this sort of revelation. And yet, as a whole, we de facto continue to trust in opaque entities that provide valuable yet likely compromised services because it is convenient.

The US government has had essentially unfettered access to landline communications since 1928[1]. See also: [2]

1. https://en.wikipedia.org/wiki/Olmstead_v._United_States 2. http://scarinciattorney.com/olmstead-v-united-states-and-the...

Re: Secret Code Found in Juniper's Firewalls Shows Risk of Government Backdoors

#112
post #108

Earlier quoted context omitted.

Not really the page I linked had ~10 people age 40+: age 36 SEPT. 28, 2012 Andrew Engeldinger 6 killed, 2 injured age 43 APRIL 2, 2012 7 killed, 3 injured: Oakland age 41 OCT. 12, 2011 Scott Dekraai, 8 killed, 1 injured: Seal Beach, Calif. age 34 AUG. 3, 2010 Omar S. Thornton, 6 killed, 11 injured: Tucson, Ariz. age 45 FEB. 12, 2010 Amy Bishop 45: 3 killed, 3 wounded: Huntsville, Ala. age 39 November 5, 2009 Nidal Ma…

Do you know why they listed these specifically? All the title says is "here are some of the deadliest ..." Even if you don't subscribe to the "more than once a day" statistic (which does include gang violence), it's still "about once a week" in 2015 for non-gang completely-innocent random victims -- and yet, this page lists only about 5 a year.

If you talking about 5 or fewer people being involved then it's not exactly a mass shooting. And at that point you might as well start looking into car accidents or even jaywalking and realize untreated depressed people are younger and simply do less stuff. So, even a successful treatment without side effects is going to look bad on a lot of violent crime statistics.

something something heatmap. https://xkcd.com/1138/

Re: Secret Code Found in Juniper's Firewalls Shows Risk of Government Backdoors

#113

Earlier quoted context omitted.

I wish we had something that tracked news articles and noted when they changed without either an inline note about the change or an update at the end. It would be like the snopes of news journalism, and we could get some really interesting statistics from that with regard to the journalistic integrity of different sources. There's a large population of people that could do with some good evidence to force them to be…

It would be like, like a wiki, but before the admins go off the reservation.

Eh, I think it has to be third-party for exactly that reason. You can never rely on the admins not going off-reservation,or being explicitly ordered to hide changes. If an organization is willing to update a story to change major facts without any indication of such, I see no reason to trust they wouldn't hide change history. Sure, it may be a smaller portion of organizations on a smaller number of articles that are willing to take it to this next level, but it would be better to bypass that entirely and just have an impartial record.

Re: Secret Code Found in Juniper's Firewalls Shows Risk of Government Backdoors

#114
post #104
post #98

Earlier quoted context omitted.

I wonder if that's going to be demonstrated to be a true statement, and further whether the tampering Juniper discovered will have disabled that second step.

It seems to be a true statement: Dual EC is used to seed a X9.31 generator with 3DES, where 8 bytes are the initial seed V, and the remaining 24 are K (cf. [1]). I don't see any other usage of Dual EC other than to self-test and to seed X9.31. Oddly, you can disable the Dual EC seeding with the flag 'one-stage-rng'. But not the other way around. [1] http://csrc.nist.gov/groups/STM/cavp/documents/rng/931rngext...

Unless the backdoor disables the X9.31 stage, what's the point of tampering with the Dual EC RNG, if its outputs are going to be mangled anyways?

Re: Secret Code Found in Juniper's Firewalls Shows Risk of Government Backdoors

#115
post #104

Earlier quoted context omitted.

It seems to be a true statement: Dual EC is used to seed a X9.31 generator with 3DES, where 8 bytes are the initial seed V, and the remaining 24 are K (cf. [1]). I don't see any other usage of Dual EC other than to self-test and to seed X9.31. Oddly, you can disable the Dual EC seeding with the flag 'one-stage-rng'. But not the other way around. [1] http://csrc.nist.gov/groups/STM/cavp/documents/rng/931rngext...

Unless the backdoor disables the X9.31 stage, what's the point of tampering with the Dual EC RNG, if its outputs are going to be mangled anyways?

I don't know, it makes little sense to me too. Maybe there's some subtle flaw somewhere, which I haven't spotted. Since subtlety doesn't seem to be a thing with the changes we've seen so far, I'm not sure what to think.

Re: Secret Code Found in Juniper's Firewalls Shows Risk of Government Backdoors

#116
post #23
post #19

Earlier quoted context omitted.

And a good one. They were definitely deliberate, but the other details are not public.

If this wasn't an intentional backdoor it raises the question, what source control methods were being used and are they secure? Has Juniper been compromised on a larger scale?

That's a good question, too. I'm sure people are asking it and many others like it internally, a well.

On the outside, I think this is yet another reason to use git, which, if I recall correctly, is designed to make attacks on commit history significantly more difficult than they are with SVN and CVS.

Re: Secret Code Found in Juniper's Firewalls Shows Risk of Government Backdoors

#117
post #96

Earlier quoted context omitted.

I would disagree that surveillance is "fairly useless". Obviously, there are times when keeping a watch on potentially dangerous people is going to pay off. How many times, I can't say. The problems begin when we have a process-bound bureaucracy rather than a group of smart people, each acting on hunches and excellent information. Bureaucracies can be composed of smart people yet act stupidly. Also, there are politic…

In fiction hunches work well, in the real world there far less valuable. In terms of mass shootings Muslims are far from the most common profile. Seung-Hui Cho aged 23 for example killed 32 people and wounded 17 in VT on April 16, 2007. Jeffrey Weise, a 16-year-old killed 10 in Red Lake, Minnesota. 21 died at Columbine. Go though: http://timelines.latimes.com/deadliest-shooting-rampages/ they don't really fit just 1…

Mass murderers in the U.S. are typically the mentally ill. There are many markers: isolated, anti-social, history of mental illness, "neighbors considered him a little strange", family who are fully aware ("we always feared this would happen" or "he scared us").

Of course, you can't just go pick up every strange person and lock them away, or 20% of us might be incarcerated. But we can definitely have better scrutiny of sociopathic children in junior high and high school, and steer them into treatment that might help protect them from hurting themselves and others. We've gone from excessive incarceration back in the 1950s to inadequate attention to the mentally ill since the 1970s, when the flawed policy of mainstreaming became popular.

The Columbine massacre was perpetrated by two disturbed boys whose families suspected something. Afterwards one of their dads said "That sounds like him." Well, if you suspected violence, why didn't you do something about it sooner?

The other kind of mass murderers today are ideology-driven Muslims. 3,000 on 9/11. Dozens at a Texas base. 14 in San Bernardino. I suspect there will be many more coming. These people are quite possibly mentally ill, sociopathic, something wrong upstairs. The ideology gives them a focus for their delusions. We don't need to go after Muslims in general; we need to focus on the unstable ones who are headed for trouble.

It's going to take clear heads and a lot of work, and in my opinion the very worst approach is to sweep all these problems under the carpet and simply tap everyone's phone and email. That's just an evasion and confers a dangerous sense of complacence.

Re: Secret Code Found in Juniper's Firewalls Shows Risk of Government Backdoors

#118

Earlier quoted context omitted.

The fact that you could use Dual EC to implement a backdoor was known in 2007, but it wasn't taken especially seriously; Schneier, for instance --- long a critic of elliptic curve crypto --- publicly cast doubt on it. It is certainly not the case that any part of the US Government acknowledged anything hinky about Dual EC in 2012. The notion that Dual EC was a cryptographic standards backdoor would have been one of t…

I agree that the oracle of hindsight can often lead us astray. However, in 2007, it wasn't just known that you could implement a backdoor, but how to do so. This of course means that any constants generated after this point could not be given the benefit of the doubt since anyone could launch this attack (and I think you'll grant me that all major intelligence services knew how to create and use a similar backdoor af…

[deleted]

Re: Secret Code Found in Juniper's Firewalls Shows Risk of Government Backdoors

#119
post #74

Earlier quoted context omitted.

Excellent point. The whole episode is very instructive. On Sunday the New York Times quoted "law enforcement sources" as saying that she had made postings on her stream. The story got a huge amount of coverage and even came up during Tuesday's Republican debate. On Wednesday, FBI Director Comey described the reporting as "grabled" and clarified that no, it was just private messages -- and the Times (and others) rewro…

I wish we had something that tracked news articles and noted when they changed without either an inline note about the change or an update at the end. It would be like the snopes of news journalism, and we could get some really interesting statistics from that with regard to the journalistic integrity of different sources. There's a large population of people that could do with some good evidence to force them to be…

This exists: http://newsdiffs.org/

Re: Secret Code Found in Juniper's Firewalls Shows Risk of Government Backdoors

#120
post #86
post #56

Earlier quoted context omitted.

> They embedded the backdoor password right into it Or you know, that's just one obvious backdoor they put in, to divert from the other 2-3 non-obvious they have.

But one thing the NSA likes to say is that the backdoors they insert are only accessible to them, not to others. For example the DUAL_EC backdoor could only be exploited by the NSA. With this backdoor, now China and everyday criminals can also use it. I see the benefit of inserting multiple backdoors. But none of them should be vulnerable to rival nations.

>But one thing the NSA likes to say is that the backdoors they insert are only accessible to them, not to others.

Which is an empty statement when it comes to security principles. If you've placed a backdoor (and some are blatantly obvious if you look for it, like some SSL issues), then others can use it too. Most backdoors are not of the "we have an encrypted password only we know" variety, but of the purposeful hole to exploit.

>I see the benefit of inserting multiple backdoors. But none of them should be vulnerable to rival nations.

Except if the idea is to monitor the local population, and you do not care that much if others monitor them too.

Post reply on HN