Live data from Hacker News

Snowden leak: Cavium networking hardware may contain NSA backdoor

twitter.com

61–70 of 628 posts

Re: Snowden leak: Cavium networking hardware may contain NSA backdoor

#62
post #45

Earlier quoted context omitted.

I think at this point it's pretty safe to assume that all of the well-known network hardware is compromised.

I wonder if MikroTik would be compromised- they’re Latvian and don’t necessarily have to bow to the NSA.

> have to bow to the NSA

You don't have to bow in order to be compromised. You can be compromised without even knowing it.

Re: Snowden leak: Cavium networking hardware may contain NSA backdoor

#63
post #30

Earlier quoted context omitted.

Huawei stuff is proven to be compromised, just not by NSA, instead by China.

If anything, you probably need several layers of different, non-aligned country vendors to have some Swiss cheese model security. So some Huawei stuff, somewhere, as long as it isn't only Huawei stuff.

lmao it's like using a multi-hop VPN to hop through multiple jurisdictions, but in your own home!

Re: Snowden leak: Cavium networking hardware may contain NSA backdoor

#64

How the NSA successfully manage to prevent the Washington Post and friends from discovering and reporting on this malicious backdoor? They've been sitting on these documents for a decade. Are the journalists just that *uncurious* about the deep contents of the documents they hold exclusive access to? Was this some kind of organizational failing?

Why are you surprised that backdoors in "boring" non-consumer facing hardware didn't get much attention?

Re: Snowden leak: Cavium networking hardware may contain NSA backdoor

#65
post #52

More interestingly, Cavium (now Marvell) also designed and manufactured the HSMs which are used by the top cloud providers (such as AWS, GCP, possibly Azure too), to hold the most critical private keys: https://www.prnewswire.com/news-releases/caviums-liquidsecur...

Is there anyone here who actually thought cloud provider HSMs were secure against the provider itself or whatever nation state(s) have jurisdiction over it? It would never occur to me to even suspect that. I assume that anything I do in the cloud is absolutely transparent to the cloud provider unless it's running homomorphic encryption, which is still too slow and limited to do much that is useful. I would trust them…

If your threat model includes the nation state where you physical infrastructure is, you're hosed.

Re: Snowden leak: Cavium networking hardware may contain NSA backdoor

#66

More interestingly, Cavium (now Marvell) also designed and manufactured the HSMs which are used by the top cloud providers (such as AWS, GCP, possibly Azure too), to hold the most critical private keys: https://www.prnewswire.com/news-releases/caviums-liquidsecur...

Ayup. We use AWS CloudHSM to hold our private signing keys for deploying field upgrades to our hardware. And when we break the CI scripts I see Cavium in the AWS logs.

Now I gotta take this to our security team and figure out what to do.

Re: Snowden leak: Cavium networking hardware may contain NSA backdoor

#67
post #6

The tweet seems to imply that the entire Ubiquiti Networks line of network hardware could be compromised. That's a shame; I was thinking of installing some in my house. I'm sure that Ubiquiti's customers will not be happy if they find out that the US Govt can access their private data.

If you're not under the threat cone of nation state surveillance (like trying to exfiltrate the radar-asborbing paint formula on the F35) then I wouldn't be too concerned. "That's not the point! It's about privacy!" Sure. I'll choose it ignore the fact that our civilization is somehow still functioning in a post-nuclear world.

It's not about privacy, it's about security. If there's a backdoor in a HSM or network interface, that backdoor can be used by others as well. That might start with foreign nation states, but might eventually leak to regular private persons or entities as well.

A backdoor is an extra attack vector with often very unfavorable properties that you as a user are unaware of.

Re: Snowden leak: Cavium networking hardware may contain NSA backdoor

#68
post #6

The tweet seems to imply that the entire Ubiquiti Networks line of network hardware could be compromised. That's a shame; I was thinking of installing some in my house. I'm sure that Ubiquiti's customers will not be happy if they find out that the US Govt can access their private data.

Ubiquiti has many other problems besides this. The worst is their vendor lockin, where even basic network operations are not possible if you happen to have any non-ubiquiti hardware in your network. You should stay away.

I have a mix of Ubiquity and non-Ubiquity equipment and have no problem achieving not only basic but fairly complex networking operations.

Re: Snowden leak: Cavium networking hardware may contain NSA backdoor

#69

How the NSA successfully manage to prevent the Washington Post and friends from discovering and reporting on this malicious backdoor? They've been sitting on these documents for a decade. Are the journalists just that *uncurious* about the deep contents of the documents they hold exclusive access to? Was this some kind of organizational failing?

Well yes, why do you think the noise died after the initial hype of Snowden leaking the docs? Do you honestly believe the mechanisms of for-profit journalism lets journalists be journalists? They got to eat and in this world you don't eat by covering yesterdays news. NSA didn't have to lift a finger. Wait a few weeks and people move on to the next story, this should not be a shocking revelation to anyone.

The British intelligence agencies forced the Guardian to literally shred the laptop with the contents while they were in the swing of running headlines about the things it was revealing.

While the USA and the UK are different, I suspect there was a bit more difficult for the NSA than "didn't have to lift a finger".

Re: Snowden leak: Cavium networking hardware may contain NSA backdoor

#70
post #65
post #52

Earlier quoted context omitted.

Is there anyone here who actually thought cloud provider HSMs were secure against the provider itself or whatever nation state(s) have jurisdiction over it? It would never occur to me to even suspect that. I assume that anything I do in the cloud is absolutely transparent to the cloud provider unless it's running homomorphic encryption, which is still too slow and limited to do much that is useful. I would trust them…

If your threat model includes the nation state where you physical infrastructure is, you're hosed.

Literally hosed. There's a funny jargon term "rubber hose cryptography" that's used to refer to the cryptanalysis method where you beat someone with a rubber hose until they give you the key. It's 100% effective against all forms of cryptography including even post-quantum algorithms.
Post reply on HN