Live data from Hacker News

The NSA's Backdoor in Dual EC

twitter.com

91–95 of 95 posts

Re: The NSA's Backdoor in Dual EC

#91
post #11
post #7

The entire concept of a backdoor that only the good guys have the keys too is so moroinic as to make my blood boil. The TSA locks were picked because a photo of the keys were posted online. The NSA forced an encryption method that they knew how to defeat got pwned. Yet the backdoor method still gets bandied about like it's the one thing to save us when it is exactly what will sink us.

The attackers didn't get the keys to the back door. They actually replaced the entire door with a new door that they made, which went unnoticed (by Juniper) for 3 years, locking out the owners of the original back door too. It's a rather impressive attack.

TBH sometimes you don't think about this stuff.

Back in college, my (CS) department shared a student area with the students from the EE department, so naturally a friendly rivalry evolved.

There was a shared common area, and a private office for CS and EE each, both separated by lockable doors from the common area.

One day, we arrived to find that the EE department had left a taunting note on a desk in our (still) locked office.

At first we thought they airdropped it (since the office walls didn't reach all the way to the slightly domed ceiling), but we didn't think of the obvious: The office doors simply had their hinges on the outside. They straight up took the door off the hinges, and then put it back.

Re: The NSA's Backdoor in Dual EC

#92
post #67

Earlier quoted context omitted.

Having a convenient backdoor already integrated definitely aided the attack, but a sophisticated attacker with the ability to silently modify your codebase is a pretty bad place to start from regardless.

how would you possibly prevent such a thing? even if Juniper subjected all potential employees to clearance-like screening - that's not foolproof either.

Absolute prevention is probably impossible, but you can severely reduce the chances of successful attack by a) limiting access to security critical parts of code b) having shadow reviews of the same code (e.g. a separate team, that gets a notification every time these pieces of code are modified, and re-reviews them without notifying the original patch submitter)

Re: The NSA's Backdoor in Dual EC

#93
post #2

https://threadreaderapp.com/thread/1433470109742518273.html

thread reader app is missing the addendum. Quote: "Addendum: the White House Press Secretary was asked about this story, and their answer is “please stop asking about this story.” h/t " - https://youtu.be/Hfa6bih_gVc?t=1740 That's f*ing hilarious

The addendum appears for me.

Re: The NSA's Backdoor in Dual EC

#94
post #11

Earlier quoted context omitted.

The attackers didn't get the keys to the back door. They actually replaced the entire door with a new door that they made, which went unnoticed (by Juniper) for 3 years, locking out the owners of the original back door too. It's a rather impressive attack.

TBH sometimes you don't think about this stuff. Back in college, my (CS) department shared a student area with the students from the EE department, so naturally a friendly rivalry evolved. There was a shared common area, and a private office for CS and EE each, both separated by lockable doors from the common area. One day, we arrived to find that the EE department had left a taunting note on a desk in our (still) lo…

That reminds me of some dodgy locks I encountered at university. There was a gap between the door and the frame, and if you slid a knife down here, it would unlock the door (one of our tutors informed us of this, oddly enough). This was fixed by screwing a metal plate over the gap - of course, if you were determined enough, you could just unscrew the plate.

Re: The NSA's Backdoor in Dual EC

#95
post #33

A bit of a tangent, but why do people insist on posting these things to twitter? They are so annoying to read like that. What does twitter offer that other platforms, designed for this type of content, don't?

There are a lot of information security discussions that only take place on Twitter, so it's kind of a self-perpetuating situation.

The entire reason I signed up for a Twitter account, after something like 5 years of refusing to do so, was that I asked for some clarification on a post to Full Disclosure, and was told something to the effect of "this has already been discussed at length on Twitter". I had done a bunch of web searches already, and none of them had turned up the thread they linked to, but they were right.

I wouldn't say I'm a fan of Twitter, but because of that situation, I discovered a lot of other discussions in other fields that I wouldn't have seen otherwise, so it seems like a net positive.

Post reply on HN