Snowden leak: Cavium networking hardware may contain NSA backdoor
51–60 of 628 posts
Re: Snowden leak: Cavium networking hardware may contain NSA backdoor
#52More interestingly, Cavium (now Marvell) also designed and manufactured the HSMs which are used by the top cloud providers (such as AWS, GCP, possibly Azure too), to hold the most critical private keys: https://www.prnewswire.com/news-releases/caviums-liquidsecur...
It would never occur to me to even suspect that. I assume that anything I do in the cloud is absolutely transparent to the cloud provider unless it's running homomorphic encryption, which is still too slow and limited to do much that is useful.
I would trust them to be secure against the average "hacker" though, so they do serve some purpose. If your threat model includes nation states then you should not be trusting cloud providers at all.
Re: Snowden leak: Cavium networking hardware may contain NSA backdoor
#53Earlier quoted context omitted.
The agreement with the NSA is more likely like this: "if you don't comply, you will get arrested / fined for whatever reason (crypto exports issues or failure to comply with the law), maybe even by another authority, or journalists may discover your little things about X. If you comply we may help you with some tips occasionally to make sure our partnership is working well, or just not reveal your trade secrets to yo…
er...what? why do you think any of that has happened? we already saw this happen in public once with Qwest: https://www.eff.org/deeplinks/2007/10/qwest-ceo-nsa-punished...
https://www.theguardian.com/technology/2016/oct/04/yahoo-sec...
Both she and Yahoo’s shareholders suffered greatly for complying.
There’s also Crypto AG, which was a foreign-owned CIA front that spied on US allies:
https://www.theguardian.com/us-news/2020/feb/11/crypto-ag-ci...
The Washington Post article is now bullshit-walled, but goes into more details.
One of my favorite parts of the story is that the intelligence agency handlers needed to make sure they only hired incompetent / mediocre engineers and mathematicians at the actual company (algorithm and backdoor design was done at a US government agency that employed competent people).
One day, a brilliant woman applied for a job. She aced the interview, and there were concerns she might be too smart, but upper management hired her on the grounds that the interview results were probably spurious. She was just a woman, after all.
She ended up exposing and fixing their backdoors pretty quickly, which caused a huge containment problem for them.
Re: Snowden leak: Cavium networking hardware may contain NSA backdoor
#54Earlier quoted context omitted.
Do you think there was a list in the document neatly titled “NSA_BACKDOORS_DONT_SHARE” or something?
More likely an IC plant in the editorial office that said "NSA Backdoors Don't Share." NSA also pays the owner of the Washington Post upwards of $10 billion for cloud services
Wouldn't be more likely that a plant would actually not say that, but rather come up with something else? Seems much more likely that a plant would promote some other aspect of a leak that would be less damaging as the story. Or even possibly making part of the document dump disappear.
Re: Snowden leak: Cavium networking hardware may contain NSA backdoor
#55How the NSA successfully manage to prevent the Washington Post and friends from discovering and reporting on this malicious backdoor? They've been sitting on these documents for a decade. Are the journalists just that *uncurious* about the deep contents of the documents they hold exclusive access to? Was this some kind of organizational failing?
Our media companies are rife with intelligence agents. Corporate / State media has no incentive to make you the wiser.
Fixed that for you
Re: Snowden leak: Cavium networking hardware may contain NSA backdoor
#56Earlier quoted context omitted.
Maybe the moral of the story is that future snowdens should leak to selected law firms instead of selected journalists? If there's one organization designed to comb through large documents for details and understand the impacts to potential parties, it is law organizations. Put 2-3 in time competition to make cases out of the documents and it will be a scramble race for justice.
Law firms aren't terribly entrepreneurial. Absent somebody paying them their hourly rate, I suspect not a single document would be read. Newspapers regularly take risks deploying humans to investigate issues without any assurance there will be a story at the bottom, but even the newspaper business has less appetite for that these days (as an aside, I suspect it's that margin that the financial investors have exploite…
Personal injury guys are the most entrepreneurial people I know...
Re: Snowden leak: Cavium networking hardware may contain NSA backdoor
#57The tweet seems to imply that the entire Ubiquiti Networks line of network hardware could be compromised. That's a shame; I was thinking of installing some in my house. I'm sure that Ubiquiti's customers will not be happy if they find out that the US Govt can access their private data.
Ubiquiti has many other problems besides this. The worst is their vendor lockin, where even basic network operations are not possible if you happen to have any non-ubiquiti hardware in your network. You should stay away.
Re: Snowden leak: Cavium networking hardware may contain NSA backdoor
#58Earlier quoted context omitted.
More likely an IC plant in the editorial office that said "NSA Backdoors Don't Share." NSA also pays the owner of the Washington Post upwards of $10 billion for cloud services
>More likely an IC plant in the editorial office that said "NSA Backdoors Don't Share." Wouldn't be more likely that a plant would actually not say that, but rather come up with something else? Seems much more likely that a plant would promote some other aspect of a leak that would be less damaging as the story. Or even possibly making part of the document dump disappear.
Re: Snowden leak: Cavium networking hardware may contain NSA backdoor
#59Earlier quoted context omitted.
I think at this point it's pretty safe to assume that all of the well-known network hardware is compromised.
I wonder if MikroTik would be compromised- they’re Latvian and don’t necessarily have to bow to the NSA.