Live data from Hacker News

Spy agency ducks questions about 'back doors' in tech products

reuters.com

31–40 of 272 posts

Re: Spy agency ducks questions about 'back doors' in tech products

#31
post #15

Earlier quoted context omitted.

It has always been true that any computer connected to the internet could be accessed by an unauthorized party, even before the leaks. Disconnect from the internet and nobody is getting in, including the NSA.

Hope you have your bluetooth also turned off

And your mic and speaker. And the light sensors while you're at it. All can be used for exfiltration.

Re: Spy agency ducks questions about 'back doors' in tech products

#32
post #14

I have a friend that works for a chip company and he said he couldn’t get into details but the amount of back doors in communication companies and in chips would scare the shit out of me.

Counterpoint: I actually do work at a chip company and have never heard of any of this internally. Even from the people working on secure biometrics. Neither of these anecdotes proves anything.

The first rule of fight club is you do not talk about fight club. If a chip company was placing back doors into their products, I doubt it would be something they would talk about around the water cooler. However, if a back door was implemented on this level, if some one broke rule #1 and rule #2 of fight club, then I don't see how it would be able to be kept quite after that.

Re: Spy agency ducks questions about 'back doors' in tech products

#33
post #15

Earlier quoted context omitted.

It has always been true that any computer connected to the internet could be accessed by an unauthorized party, even before the leaks. Disconnect from the internet and nobody is getting in, including the NSA.

> Disconnect from the internet and nobody is getting in, including the NSA. Oh boy. That's some serious delusion in 2020. Wireless cards and higher end network interface cards are independent computers. Your processor has another processor (Intel ME and others) in it. Baseband Management Controllers are also independent computers on their own right. With closed firmware and wireless capabilities, you can never know w…

I'm actually kinda curious if TEMPEST attacks or similar have been used spy on citizens ever now.

Re: Spy agency ducks questions about 'back doors' in tech products

#34
I would expect they do, and I'm not entirely against it depending on the circumstances around it and so forth.

To me a 'back door' could range from 'don't fix that bug for a week' to 'push this update to this user' to some absurd 'hey can you add this remote desktop client to your code, the password has to be 1234'.

By no means is it a light thing to do but I do believe there is a range of actions that would constitute a 'back door' to me.

Granted I'm all for more congressional oversight and I'd like to see MUCH more aggressive congressional action.

Re: Spy agency ducks questions about 'back doors' in tech products

#35
post #15

Earlier quoted context omitted.

It has always been true that any computer connected to the internet could be accessed by an unauthorized party, even before the leaks. Disconnect from the internet and nobody is getting in, including the NSA.

> Disconnect from the internet and nobody is getting in, including the NSA. Oh boy. That's some serious delusion in 2020. Wireless cards and higher end network interface cards are independent computers. Your processor has another processor (Intel ME and others) in it. Baseband Management Controllers are also independent computers on their own right. With closed firmware and wireless capabilities, you can never know w…

Stuxnet is interesting. Apparently, the US and Israeli agents threw away a number of USB devices around target facilities. What do you do when you find a USB stick? Well, eventually someone working in an air gapped facility picked up one and used it inside.

The NSA apparently perfectly aligned 4 zeros days in Siemens and Microsoft products to spread the malware from USB into the Iranian LAN (shared printers, industrial PICs etc).

The fact that they could choose and align 4 zero days indicates that the NSA probably has a large list of zeros days.

Re: Spy agency ducks questions about 'back doors' in tech products

#36
post #12

Earlier quoted context omitted.

Quote from Wyden in the article >Secret encryption back doors are a threat to national security and the safety of our families – it’s only a matter of time before foreign hackers or criminals exploit them in ways that undermine American national security

In other words: NSA paved the way for foreign hackers and criminals...

It's certainly possible, but I suspect just traditional bugs and poor software is more likely the cause for such events.

Software / hardware industry is PLENTY good at paving the way all on its own.

Re: Spy agency ducks questions about 'back doors' in tech products

#37

The director of the NSA lied while under oath to congress, and nothing happened. As far as I'm concerned, what 3 letter agencies say publically is irrelevant.

It's an interesting case of cognitive dissonance. Most will admit when pressed a bit that the CIA/NSA/FBI do not have our best interests at heart and are out of control. They have repeatedly lied under oath, lied to congress, lied to the public, run human experiments on unwitting citizens, collect data on all of us, etc with complete impunity.

However many people somehow simultaneously hold the belief that these agencies should continue to exist, are deserving of our taxpayer dollars, and are generally Good Guys who happen to do bad things sometimes. Perhaps it's just too exhausting to consider the extent of corruption in the USA.

Re: Spy agency ducks questions about 'back doors' in tech products

#38
post #14

Earlier quoted context omitted.

Counterpoint: I actually do work at a chip company and have never heard of any of this internally. Even from the people working on secure biometrics. Neither of these anecdotes proves anything.

The first rule of fight club is you do not talk about fight club. If a chip company was placing back doors into their products, I doubt it would be something they would talk about around the water cooler. However, if a back door was implemented on this level, if some one broke rule #1 and rule #2 of fight club, then I don't see how it would be able to be kept quite after that.

So we only believe people who claim something is happening with no proof ... because anyone who doesn't see it happening just isn't in the special circle of folks doing it?

Re: Spy agency ducks questions about 'back doors' in tech products

#39
post #34

I would expect they do, and I'm not entirely against it depending on the circumstances around it and so forth. To me a 'back door' could range from 'don't fix that bug for a week' to 'push this update to this user' to some absurd 'hey can you add this remote desktop client to your code, the password has to be 1234'. By no means is it a light thing to do but I do believe there is a range of actions that would constitu…

The problem with your first and third examples is that it leaves it open and vulnerable to anyone other than the NSA. Like if a "backdoor" is left open for encryption, as soon as it's discovered then that door is open to anyone.

The problem with your second example, targeting a specific user, is that they're doing this without any kind of warrant.

Re: Spy agency ducks questions about 'back doors' in tech products

#40
post #34

I would expect they do, and I'm not entirely against it depending on the circumstances around it and so forth. To me a 'back door' could range from 'don't fix that bug for a week' to 'push this update to this user' to some absurd 'hey can you add this remote desktop client to your code, the password has to be 1234'. By no means is it a light thing to do but I do believe there is a range of actions that would constitu…

The problem with your first and third examples is that it leaves it open and vulnerable to anyone other than the NSA. Like if a "backdoor" is left open for encryption, as soon as it's discovered then that door is open to anyone. The problem with your second example, targeting a specific user, is that they're doing this without any kind of warrant.

I completely agree on all points.
Post reply on HN