Live data from Hacker News

Snowden leak: Cavium networking hardware may contain NSA backdoor

twitter.com

71–80 of 628 posts

Re: Snowden leak: Cavium networking hardware may contain NSA backdoor

#71
Looking more closely at this, the backdoor is almost certainly based on the back-doored random number generator, Dual_EC_DRBG, which is implemented as NIST SP 800-90A.

From Wiki: >>> NIST SP 800-90A ("SP" stands for "special publication") is a publication by the National Institute of Standards and Technology with the title Recommendation for Random Number Generation Using Deterministic Random Bit Generators. The publication contains the specification for three allegedly cryptographically secure pseudorandom number generators for use in cryptography: Hash DRBG (based on hash functions), HMAC DRBG (based on HMAC), and CTR DRBG (based on block ciphers in counter mode). Earlier versions included a fourth generator, Dual_EC_DRBG (based on elliptic curve cryptography). Dual_EC_DRBG was later reported to probably contain a kleptographic backdoor inserted by the United States National Security Agency (NSA).

From Cavium's NIST FIPS-140-2, Section 3.3 [1] Approved and Allowed Algorithms:

The cryptographic module supports the following FIPS Approved algorithms.

*SP800-90 CTR DRBG Deterministic random number generation 32

1: https://csrc.nist.gov/csrc/media/projects/cryptographic-modu...

Re: Snowden leak: Cavium networking hardware may contain NSA backdoor

#72
Another tragic blow to the environment and economy.

We treat these stories as if they were simple matters of politics and tech. But the blast radius is huge. When this happened to Cisco, and their value dropped to about 7% of the market they created, I passed massive dumpsters of Cisco gear in the car park, prematurely torn out of racks and consigned to crushing as e-waste.

Has anyone done a serious cost analysis of just how hard this hits? If a foreign entity sabotaged our industry this way we'd take the battle right to them.

Re: Snowden leak: Cavium networking hardware may contain NSA backdoor

#73

How the NSA successfully manage to prevent the Washington Post and friends from discovering and reporting on this malicious backdoor? They've been sitting on these documents for a decade. Are the journalists just that *uncurious* about the deep contents of the documents they hold exclusive access to? Was this some kind of organizational failing?

Our media companies are rife with intelligence agents. Corporate / State media has no incentive to make you the wiser.

It's quite a bit more subtle than that. News organization have their sources that are in the intelligence community. They use each other. Sometimes the journalist wants to use their sources for information. Other times their sources feed them disinformation disguised as information. Other times they want a back channel to leak some real information but can't be seem as coming from a government source. Being a good journalist is hard and often doesn't pay very well.

I'm often remind of PG's essay on corporate PR and the media: http://www.paulgraham.com/submarine.html

Re: Snowden leak: Cavium networking hardware may contain NSA backdoor

#74
Very impressive work by the NSA, if true. Both from a political and technical perspective. It's good to know that our intelligence services are doing what they're supposed to, and doing it well.

However, as interesting as this revelation is, it's unfortunate that Snowden decided to defect to the Russians and share his stolen cache of top secret documents with them and China, using Western journalists as ideological cover. I look forward to the day when he is brought to justice for treason.

Re: Snowden leak: Cavium networking hardware may contain NSA backdoor

#75

How the NSA successfully manage to prevent the Washington Post and friends from discovering and reporting on this malicious backdoor? They've been sitting on these documents for a decade. Are the journalists just that *uncurious* about the deep contents of the documents they hold exclusive access to? Was this some kind of organizational failing?

Snowden leaked a shit ton of documents, the vast majority of which had absolutely nothing to do with any kind of NSA wrongdoing. Journalists then had to go through and try to figure out what these documents actually meant (which they frequently misunderstood). Obviously they're still doing it to today.

Re: Snowden leak: Cavium networking hardware may contain NSA backdoor

#76
post #30

Earlier quoted context omitted.

Huawei stuff is proven to be compromised, just not by NSA, instead by China.

If anything, you probably need several layers of different, non-aligned country vendors to have some Swiss cheese model security. So some Huawei stuff, somewhere, as long as it isn't only Huawei stuff.

This is a great idea in that they’ll likely also patch their stuff when they discover the other team has exploited it.

Re: Snowden leak: Cavium networking hardware may contain NSA backdoor

#78
post #45

Earlier quoted context omitted.

I think at this point it's pretty safe to assume that all of the well-known network hardware is compromised.

I wonder if MikroTik would be compromised- they’re Latvian and don’t necessarily have to bow to the NSA.

Joking? LOL

https://thehackernews.com/2023/07/critical-mikrotik-routeros...

Re: Snowden leak: Cavium networking hardware may contain NSA backdoor

#79
post #6

The tweet seems to imply that the entire Ubiquiti Networks line of network hardware could be compromised. That's a shame; I was thinking of installing some in my house. I'm sure that Ubiquiti's customers will not be happy if they find out that the US Govt can access their private data.

Pretty sure only the EdgeRouter and some of the older Unifi Security Gateways use Cavium chips. Most of the newer stuff (like the Dream Machine line) I don't think are anymore. None of the Unifi APs did either I don't think (the U6 ones have Mediatek chips in them)
Post reply on HN