Do we need to do this every day?
Every fucking day until democracy kicks in.
Snowden leak: Cavium networking hardware may contain NSA backdoor
61–70 of 628 posts
Re: Snowden leak: Cavium networking hardware may contain NSA backdoor
#62Earlier quoted context omitted.
I think at this point it's pretty safe to assume that all of the well-known network hardware is compromised.
I wonder if MikroTik would be compromised- they’re Latvian and don’t necessarily have to bow to the NSA.
You don't have to bow in order to be compromised. You can be compromised without even knowing it.
Re: Snowden leak: Cavium networking hardware may contain NSA backdoor
#63Earlier quoted context omitted.
Huawei stuff is proven to be compromised, just not by NSA, instead by China.
If anything, you probably need several layers of different, non-aligned country vendors to have some Swiss cheese model security. So some Huawei stuff, somewhere, as long as it isn't only Huawei stuff.
Re: Snowden leak: Cavium networking hardware may contain NSA backdoor
#64How the NSA successfully manage to prevent the Washington Post and friends from discovering and reporting on this malicious backdoor? They've been sitting on these documents for a decade. Are the journalists just that *uncurious* about the deep contents of the documents they hold exclusive access to? Was this some kind of organizational failing?
Re: Snowden leak: Cavium networking hardware may contain NSA backdoor
#65More interestingly, Cavium (now Marvell) also designed and manufactured the HSMs which are used by the top cloud providers (such as AWS, GCP, possibly Azure too), to hold the most critical private keys: https://www.prnewswire.com/news-releases/caviums-liquidsecur...
Is there anyone here who actually thought cloud provider HSMs were secure against the provider itself or whatever nation state(s) have jurisdiction over it? It would never occur to me to even suspect that. I assume that anything I do in the cloud is absolutely transparent to the cloud provider unless it's running homomorphic encryption, which is still too slow and limited to do much that is useful. I would trust them…
Re: Snowden leak: Cavium networking hardware may contain NSA backdoor
#66More interestingly, Cavium (now Marvell) also designed and manufactured the HSMs which are used by the top cloud providers (such as AWS, GCP, possibly Azure too), to hold the most critical private keys: https://www.prnewswire.com/news-releases/caviums-liquidsecur...
Now I gotta take this to our security team and figure out what to do.
Re: Snowden leak: Cavium networking hardware may contain NSA backdoor
#67The tweet seems to imply that the entire Ubiquiti Networks line of network hardware could be compromised. That's a shame; I was thinking of installing some in my house. I'm sure that Ubiquiti's customers will not be happy if they find out that the US Govt can access their private data.
If you're not under the threat cone of nation state surveillance (like trying to exfiltrate the radar-asborbing paint formula on the F35) then I wouldn't be too concerned. "That's not the point! It's about privacy!" Sure. I'll choose it ignore the fact that our civilization is somehow still functioning in a post-nuclear world.
A backdoor is an extra attack vector with often very unfavorable properties that you as a user are unaware of.
Re: Snowden leak: Cavium networking hardware may contain NSA backdoor
#68The tweet seems to imply that the entire Ubiquiti Networks line of network hardware could be compromised. That's a shame; I was thinking of installing some in my house. I'm sure that Ubiquiti's customers will not be happy if they find out that the US Govt can access their private data.
Ubiquiti has many other problems besides this. The worst is their vendor lockin, where even basic network operations are not possible if you happen to have any non-ubiquiti hardware in your network. You should stay away.
Re: Snowden leak: Cavium networking hardware may contain NSA backdoor
#69How the NSA successfully manage to prevent the Washington Post and friends from discovering and reporting on this malicious backdoor? They've been sitting on these documents for a decade. Are the journalists just that *uncurious* about the deep contents of the documents they hold exclusive access to? Was this some kind of organizational failing?
Well yes, why do you think the noise died after the initial hype of Snowden leaking the docs? Do you honestly believe the mechanisms of for-profit journalism lets journalists be journalists? They got to eat and in this world you don't eat by covering yesterdays news. NSA didn't have to lift a finger. Wait a few weeks and people move on to the next story, this should not be a shocking revelation to anyone.
While the USA and the UK are different, I suspect there was a bit more difficult for the NSA than "didn't have to lift a finger".
Re: Snowden leak: Cavium networking hardware may contain NSA backdoor
#70Earlier quoted context omitted.
Is there anyone here who actually thought cloud provider HSMs were secure against the provider itself or whatever nation state(s) have jurisdiction over it? It would never occur to me to even suspect that. I assume that anything I do in the cloud is absolutely transparent to the cloud provider unless it's running homomorphic encryption, which is still too slow and limited to do much that is useful. I would trust them…
If your threat model includes the nation state where you physical infrastructure is, you're hosed.