Live data from Hacker News

Spy agency ducks questions about 'back doors' in tech products

reuters.com

51–60 of 272 posts

Re: Spy agency ducks questions about 'back doors' in tech products

#51
They say it’s for large scale cloud management, but, think of worst case scenario:

https://www.zdnet.com/article/minix-intels-hidden-in-chip-op...

It seems like a massive waste of chip transistors and R&D with limited gain. The hidden minix OS runs at a higher privilege than your host OS. Even if your data is encrypted, any time you decrypt locally, they can see it. I get it, they are looking for bad guys, what if the bad guys take over? There will be nowhere to hide. Yes, I am wearing a tinfoil hat.

Re: Spy agency ducks questions about 'back doors' in tech products

#52
post #5

"The tactics drew widespread attention starting in 2013, when Snowden leaked documents referencing these practices." So this is what Snowden has done: he "drew widespread attention to these tactics". Before Snowden they would call you "paranoid" if you would allow yourself to mention it. Today they can not call you paranoid anymore. And yes, it has hurt US industry reputation. Many don't trust Intel processors and Ci…

> Many don't trust Intel processors and Cisco routers anymore

That's Cisco's own fault given that there are rarely more than 6 months between critical firmware releases that either have some way of hardcoded backdoor account, remote code execution or other similar bugs.

Re: Spy agency ducks questions about 'back doors' in tech products

#53
post #5

"The tactics drew widespread attention starting in 2013, when Snowden leaked documents referencing these practices." So this is what Snowden has done: he "drew widespread attention to these tactics". Before Snowden they would call you "paranoid" if you would allow yourself to mention it. Today they can not call you paranoid anymore. And yes, it has hurt US industry reputation. Many don't trust Intel processors and Ci…

"Sometimes paranoia's just having all the facts" - William S Burroughs

Re: Spy agency ducks questions about 'back doors' in tech products

#54
post #22

Earlier quoted context omitted.

a little interdiction while that new airgapped laptop is shipped to you and they got you, even though you never connected to a network

Exactly what have they got, if you never connect it to a network afterward, either? A key-log that never makes it back to them? (I’m presuming here that the laptop is openable, and that you will do so and physically remove any wi-fi M.2 card from it — and associated antennae — since you won’t be using it. There might be some sort of extra surface-mount snooper chip left onboard that could replicate the same function…

Perhaps with something like this?

https://www.schneier.com/blog/archives/2014/03/ragemaster_ns...

Or this?

https://www.schneier.com/blog/archives/2014/03/cottonmouth-i...

If you have actually attracted the attention of the NSA, pulling your NIC is playground stuff.

Re: Spy agency ducks questions about 'back doors' in tech products

#55
post #38

Earlier quoted context omitted.

So we only believe people who claim something is happening with no proof ... because anyone who doesn't see it happening just isn't in the special circle of folks doing it?

what are you on about? if nobody in the know talks, how does anyone find out about it? if people are talking about it, then anyone with any know-how will start to investigate. if you choose to believe something someone tells you with no proof, then that's on you. claiming we do the same thing is a broad brush that i'm not getting painted on by thank you very much

I don't understand what you're saying.

We had one anecdote saying a thing is happening, the second from someone who says it isn't. Your post seemed to indicate that the second post isn't true because maybe that person just doesn't know about it.

That seems to refute the second and assume the first is true.

Re: Spy agency ducks questions about 'back doors' in tech products

#56
Operate under the assumption that government is reading all of your text messages, internet history, payment history, and phone calls. Then when you need privacy, enhance as needed. Even if privacy technologies like VPN or Tor are compromised, the government is less likely to reveal in order to keep the fact they can do it secret. Good luck out there! It's an unfair and scary world, once you try to do anything non-conformist.

Re: Spy agency ducks questions about 'back doors' in tech products

#57
post #5

"The tactics drew widespread attention starting in 2013, when Snowden leaked documents referencing these practices." So this is what Snowden has done: he "drew widespread attention to these tactics". Before Snowden they would call you "paranoid" if you would allow yourself to mention it. Today they can not call you paranoid anymore. And yes, it has hurt US industry reputation. Many don't trust Intel processors and Ci…

They totally still call you paranoid. Snowden unfortunately meant nothing to the general technology consumer mass. They're more than happy to defend tooth and nail their jails. See Discord or Zoom as prime current examples. It is ridiculous that he had to go through this just for people to shake their shoulders and keep on, except for the few that already were inclined to care.

Look, my estimation of "general technology consumer mass" is incredibly low, but I promise you nearly every American adult knows who Edward Snowden is and probably has at least a vague idea of what he was trying to communicate. I agree that many — maybe even most — people don't understand the issue very well, but I think it did have a pretty large impact at the time and since.

Re: Spy agency ducks questions about 'back doors' in tech products

#58

I have a friend that works for a chip company and he said he couldn’t get into details but the amount of back doors in communication companies and in chips would scare the shit out of me.

I question this. Actually I'm going to assert this is only true if your friend is referring to hidden back doors that he believes exist. I don't believe any employee of a chip company is aware of a back door knowingly added to their own product (with one exception see below). I say this because NSA seems more clever than that, and because any scheme to explicitly add back doors is bound to be eventually exposed. Inst…

> I don't believe any employee of a chip company is aware of a back door knowingly added to their own product (with one exception see below).

Most if not all ICs above a certain intelligence level have JTAG, which effectively is a backdoor. All you now need is (for those chips that support it, in the first place...) a way to bypass the OTP fuses "preventing" JTAG access - this kind of vulnerability turns out often enough to be saying it's commonplace.

Re: Spy agency ducks questions about 'back doors' in tech products

#59
post #48

Earlier quoted context omitted.

Yes. After the Snowden leaks and Shadowbrokers/Vault7/WannaCry disasters, the agencies put a lot of effort into reassuring the public that US technology was trustworthy. This included things like making public the Vulnerabilities Equities Process [1], and other work to restore trust in cryptographic standards agencies like NIST [2]. It also included more public engagement with industry to report serious vulnerabiliti…

Couldn't they just have said "no we have no backdoors"? NSA would look good, Congress would look good for asking the tough questions. When eventually new evidence comes to light that they do have backdoors, they have the choice then between continuing to deny deny deny, or pointing to national security interests.

>Couldn't they just have said "no we have no backdoors"?

No, because once their backdoors are (inevitably) going to be found/leaked, they'll come off as liars. Plus, if they would have said no, nobody would buy that or would think they're asleep at the wheel.

Re: Spy agency ducks questions about 'back doors' in tech products

#60
post #15
post #5

"The tactics drew widespread attention starting in 2013, when Snowden leaked documents referencing these practices." So this is what Snowden has done: he "drew widespread attention to these tactics". Before Snowden they would call you "paranoid" if you would allow yourself to mention it. Today they can not call you paranoid anymore. And yes, it has hurt US industry reputation. Many don't trust Intel processors and Ci…

It has always been true that any computer connected to the internet could be accessed by an unauthorized party, even before the leaks. Disconnect from the internet and nobody is getting in, including the NSA.

> Disconnect from the internet and nobody is getting in, including the NSA.

Wait until they put 5g chips in every single product to make them "smart". Few people talk about that but I believe it's the main use case for 5g. Everything will be connected and you'll have no way to opt out

> 4G can support about 4,000 devices per square kilometre, whereas 5G will support around one million

Post reply on HN