Live data from Hacker News

Snowden leak: Cavium networking hardware may contain NSA backdoor

twitter.com

51–60 of 628 posts

Re: Snowden leak: Cavium networking hardware may contain NSA backdoor

#52

More interestingly, Cavium (now Marvell) also designed and manufactured the HSMs which are used by the top cloud providers (such as AWS, GCP, possibly Azure too), to hold the most critical private keys: https://www.prnewswire.com/news-releases/caviums-liquidsecur...

Is there anyone here who actually thought cloud provider HSMs were secure against the provider itself or whatever nation state(s) have jurisdiction over it?

It would never occur to me to even suspect that. I assume that anything I do in the cloud is absolutely transparent to the cloud provider unless it's running homomorphic encryption, which is still too slow and limited to do much that is useful.

I would trust them to be secure against the average "hacker" though, so they do serve some purpose. If your threat model includes nation states then you should not be trusting cloud providers at all.

Re: Snowden leak: Cavium networking hardware may contain NSA backdoor

#53
post #15

Earlier quoted context omitted.

The agreement with the NSA is more likely like this: "if you don't comply, you will get arrested / fined for whatever reason (crypto exports issues or failure to comply with the law), maybe even by another authority, or journalists may discover your little things about X. If you comply we may help you with some tips occasionally to make sure our partnership is working well, or just not reveal your trade secrets to yo…

er...what? why do you think any of that has happened? we already saw this happen in public once with Qwest: https://www.eff.org/deeplinks/2007/10/qwest-ceo-nsa-punished...

It’s happened at least three times. They got Yahoo’s CEO to [bypass SOX compliance and] hand over access to 500 million email accounts. Last I heard, she said they convinced her she wasn’t allowed to ask corporate lawyers for guidance.

https://www.theguardian.com/technology/2016/oct/04/yahoo-sec...

Both she and Yahoo’s shareholders suffered greatly for complying.

There’s also Crypto AG, which was a foreign-owned CIA front that spied on US allies:

https://www.theguardian.com/us-news/2020/feb/11/crypto-ag-ci...

The Washington Post article is now bullshit-walled, but goes into more details.

One of my favorite parts of the story is that the intelligence agency handlers needed to make sure they only hired incompetent / mediocre engineers and mathematicians at the actual company (algorithm and backdoor design was done at a US government agency that employed competent people).

One day, a brilliant woman applied for a job. She aced the interview, and there were concerns she might be too smart, but upper management hired her on the grounds that the interview results were probably spurious. She was just a woman, after all.

She ended up exposing and fixing their backdoors pretty quickly, which caused a huge containment problem for them.

Re: Snowden leak: Cavium networking hardware may contain NSA backdoor

#54
post #29

Earlier quoted context omitted.

Do you think there was a list in the document neatly titled “NSA_BACKDOORS_DONT_SHARE” or something?

More likely an IC plant in the editorial office that said "NSA Backdoors Don't Share." NSA also pays the owner of the Washington Post upwards of $10 billion for cloud services

>More likely an IC plant in the editorial office that said "NSA Backdoors Don't Share."

Wouldn't be more likely that a plant would actually not say that, but rather come up with something else? Seems much more likely that a plant would promote some other aspect of a leak that would be less damaging as the story. Or even possibly making part of the document dump disappear.

Re: Snowden leak: Cavium networking hardware may contain NSA backdoor

#55

How the NSA successfully manage to prevent the Washington Post and friends from discovering and reporting on this malicious backdoor? They've been sitting on these documents for a decade. Are the journalists just that *uncurious* about the deep contents of the documents they hold exclusive access to? Was this some kind of organizational failing?

Our media companies are rife with intelligence agents. Corporate / State media has no incentive to make you the wiser.

> Our media companies are run by intelligence agents

Fixed that for you

Re: Snowden leak: Cavium networking hardware may contain NSA backdoor

#56
post #19

Earlier quoted context omitted.

Maybe the moral of the story is that future snowdens should leak to selected law firms instead of selected journalists? If there's one organization designed to comb through large documents for details and understand the impacts to potential parties, it is law organizations. Put 2-3 in time competition to make cases out of the documents and it will be a scramble race for justice.

Law firms aren't terribly entrepreneurial. Absent somebody paying them their hourly rate, I suspect not a single document would be read. Newspapers regularly take risks deploying humans to investigate issues without any assurance there will be a story at the bottom, but even the newspaper business has less appetite for that these days (as an aside, I suspect it's that margin that the financial investors have exploite…

>Law firms aren't terribly entrepreneurial.

Personal injury guys are the most entrepreneurial people I know...

Re: Snowden leak: Cavium networking hardware may contain NSA backdoor

#57
post #6

The tweet seems to imply that the entire Ubiquiti Networks line of network hardware could be compromised. That's a shame; I was thinking of installing some in my house. I'm sure that Ubiquiti's customers will not be happy if they find out that the US Govt can access their private data.

Ubiquiti has many other problems besides this. The worst is their vendor lockin, where even basic network operations are not possible if you happen to have any non-ubiquiti hardware in your network. You should stay away.

Can you provide an example of this issue? This has not been my experience.

Re: Snowden leak: Cavium networking hardware may contain NSA backdoor

#58
post #29

Earlier quoted context omitted.

More likely an IC plant in the editorial office that said "NSA Backdoors Don't Share." NSA also pays the owner of the Washington Post upwards of $10 billion for cloud services

>More likely an IC plant in the editorial office that said "NSA Backdoors Don't Share." Wouldn't be more likely that a plant would actually not say that, but rather come up with something else? Seems much more likely that a plant would promote some other aspect of a leak that would be less damaging as the story. Or even possibly making part of the document dump disappear.

[deleted]

Re: Snowden leak: Cavium networking hardware may contain NSA backdoor

#59
post #45

Earlier quoted context omitted.

I think at this point it's pretty safe to assume that all of the well-known network hardware is compromised.

I wonder if MikroTik would be compromised- they’re Latvian and don’t necessarily have to bow to the NSA.

Several MikroTik routers use marvel hardware underneath. So marvel might be compelled to backdoor the hardware for the NSA.

Re: Snowden leak: Cavium networking hardware may contain NSA backdoor

#60
When I buy something electronic, my approach is "everything that is closed and goes online will be used to spy on people". It may seem a stretch, but governments can't exercise power over something they cannot control, and truly private communications would take away some of that control. To me there are no conspiracy theories or other strange reasons for being able to decrypt any seemingly private information except the will to preserve the status quo at any cost, which implies knowing in advance what a potential adversary may think or do. I would expect every device to be bugged for that reason, including all cellphones and computers and associated hardware, from CPUs with closed subsystems down to network chipsets with closed firmware. There will be no way to ensure private communications until someone will find a way to make a device which is 100% open and auditable from the operating system to the CPU, from all chipsets down to the last screw.
Post reply on HN