Live data from Hacker News

Snowden leak: Cavium networking hardware may contain NSA backdoor

twitter.com

91–100 of 628 posts

Re: Snowden leak: Cavium networking hardware may contain NSA backdoor

#91

How the NSA successfully manage to prevent the Washington Post and friends from discovering and reporting on this malicious backdoor? They've been sitting on these documents for a decade. Are the journalists just that *uncurious* about the deep contents of the documents they hold exclusive access to? Was this some kind of organizational failing?

Are you kidding? WaPo serves the intelligence community.

>After creation of the CIA in 1947, it enjoyed direct collaboration with many U.S. news organizations. But the agency faced a major challenge in October 1977, when—soon after leaving the Washington Post—famed Watergate reporter Carl Bernstein provided an extensive exposé in Rolling Stone.

Citing CIA documents, Bernstein wrote that during the previous 25 years “more than 400 American journalists…have secretly carried out assignments for the Central Intelligence Agency.” He added: “The history of the CIA’s involvement with the American press continues to be shrouded by an official policy of obfuscation and deception.”

Bernstein’s story tarnished the reputations of many journalists and media institutions, including the Washington Post and New York Times. While the CIA’s mission was widely assumed to involve “obfuscation and deception,” the mission of the nation’s finest newspapers was ostensibly the opposite.

https://www.guernicamag.com/normon-solomon-why-the-washingto...

Re: Snowden leak: Cavium networking hardware may contain NSA backdoor

#92
post #30

Earlier quoted context omitted.

Huawei stuff is proven to be compromised, just not by NSA, instead by China.

a CIA claim isn't "proof". I've never seen anything to prove it, just imperialist hysterics

It is fair to think that if the CIA is compromising US companies, then China is likely doing the same to Chinese companies. To assume otherwise is wishful thinking.

Re: Snowden leak: Cavium networking hardware may contain NSA backdoor

#93

Why now? Looks like Snowden is being weaponized, wich might indicate that he is still part of the group he is denouncing, is he a psyop? What's the goal?

From one of Twitter replies:

>... this is not new... It states in the article that this thesis from Jacob R. Appelbaum was released March 25, 2022. The only thing that makes these 'new' (?) is that electrospaces discussed September 14th

https://twitter.com/vxunderground/status/1703995620250325405

Electrospaces article discussion: https://news.ycombinator.com/item?id=37562225

Re: Snowden leak: Cavium networking hardware may contain NSA backdoor

#94
post #52

More interestingly, Cavium (now Marvell) also designed and manufactured the HSMs which are used by the top cloud providers (such as AWS, GCP, possibly Azure too), to hold the most critical private keys: https://www.prnewswire.com/news-releases/caviums-liquidsecur...

Is there anyone here who actually thought cloud provider HSMs were secure against the provider itself or whatever nation state(s) have jurisdiction over it? It would never occur to me to even suspect that. I assume that anything I do in the cloud is absolutely transparent to the cloud provider unless it's running homomorphic encryption, which is still too slow and limited to do much that is useful. I would trust them…

Lots of people believe that. They believe truthfully you can get to the level of AWS, MS, Google, Facebook or Apple whilst standing up to the nations that host those companies. I've walked into government employees in the hallways of tiny ISPs, I see no reason to believe at all that larger companies are any different except for when easier backdoors have been installed.

Re: Snowden leak: Cavium networking hardware may contain NSA backdoor

#95
post #90
post #70

Earlier quoted context omitted.

Literally hosed. There's a funny jargon term "rubber hose cryptography" that's used to refer to the cryptanalysis method where you beat someone with a rubber hose until they give you the key. It's 100% effective against all forms of cryptography including even post-quantum algorithms.

That's actually not true. It can do nothing about M of N cryptography. (That's when a key is broken up such that there are N parts, and at least M (less than N) are required to decrypt. It doesn't matter how many rubber hoses you have, one person can fully divulge or give access to their key and it's still safe.

Sure, so you hit all of the people that have all of the pieces. Problem solved.

Re: Snowden leak: Cavium networking hardware may contain NSA backdoor

#96
post #90
post #70

Earlier quoted context omitted.

Literally hosed. There's a funny jargon term "rubber hose cryptography" that's used to refer to the cryptanalysis method where you beat someone with a rubber hose until they give you the key. It's 100% effective against all forms of cryptography including even post-quantum algorithms.

That's actually not true. It can do nothing about M of N cryptography. (That's when a key is broken up such that there are N parts, and at least M (less than N) are required to decrypt. It doesn't matter how many rubber hoses you have, one person can fully divulge or give access to their key and it's still safe.

That situation just requires a longer hose

Re: Snowden leak: Cavium networking hardware may contain NSA backdoor

#97

When I buy something electronic, my approach is "everything that is closed and goes online will be used to spy on people". It may seem a stretch, but governments can't exercise power over something they cannot control, and truly private communications would take away some of that control. To me there are no conspiracy theories or other strange reasons for being able to decrypt any seemingly private information except…

“100% open and auditable from the operating system to the cpu” is the main goal of the Betrusted project: https://betrusted.io/

Re: Snowden leak: Cavium networking hardware may contain NSA backdoor

#98

Very impressive work by the NSA, if true. Both from a political and technical perspective. It's good to know that our intelligence services are doing what they're supposed to, and doing it well. However, as interesting as this revelation is, it's unfortunate that Snowden decided to defect to the Russians and share his stolen cache of top secret documents with them and China, using Western journalists as ideological c…

[flagged]

Re: Snowden leak: Cavium networking hardware may contain NSA backdoor

#99

More interestingly, Cavium (now Marvell) also designed and manufactured the HSMs which are used by the top cloud providers (such as AWS, GCP, possibly Azure too), to hold the most critical private keys: https://www.prnewswire.com/news-releases/caviums-liquidsecur...

Ayup. We use AWS CloudHSM to hold our private signing keys for deploying field upgrades to our hardware. And when we break the CI scripts I see Cavium in the AWS logs. Now I gotta take this to our security team and figure out what to do.

I'd be surprised if you get anything more than generic statements about how they take security very seriously and they are open to suggestions, but avoid addressing the mentioned concerns directly (and this applies to all cloud providers out there, not just AWS).

I'm sure a few others here would like to see their response as well.

Re: Snowden leak: Cavium networking hardware may contain NSA backdoor

#100

Earlier quoted context omitted.

Ayup. We use AWS CloudHSM to hold our private signing keys for deploying field upgrades to our hardware. And when we break the CI scripts I see Cavium in the AWS logs. Now I gotta take this to our security team and figure out what to do.

I'd be surprised if you get anything more than generic statements about how they take security very seriously and they are open to suggestions, but avoid addressing the mentioned concerns directly (and this applies to all cloud providers out there, not just AWS). I'm sure a few others here would like to see their response as well.

We've had other issues with our CloudHSM instance, especially with the PKCS1.5 deprecation on January 1. And their support has been pretty dismal. Not expecting much from them at this point.
Post reply on HN