Live data from Hacker News

Snowden leak: Cavium networking hardware may contain NSA backdoor

twitter.com

101–110 of 628 posts

Re: Snowden leak: Cavium networking hardware may contain NSA backdoor

#102

Looking more closely at this, the backdoor is almost certainly based on the back-doored random number generator, Dual_EC_DRBG, which is implemented as NIST SP 800-90A. From Wiki: >>> NIST SP 800-90A ("SP" stands for "special publication") is a publication by the National Institute of Standards and Technology with the title Recommendation for Random Number Generation Using Deterministic Random Bit Generators. The publ…

That's a very specific module - one of Cavium's dozens and dozens of products. Hard to tell what it is, more information is needed.

Well, there's several Cavium devices that support the deprecated/back-doored Hash_DRBG.

For example, these devices were validated for the completely appropriately named "SonicOS 6.2.5 for TZ, SM and NSA". Gotta appreciate the irony.

Cavium CN7020 Hash DRBG

Cavium CN7130 Hash DRBG

Cavium Octeon Plus CN66XX Family Hash DRBG

Cavium Octeon Plus CN68XX Family Hash DRBG

I don't know if that's hardware support or just a software validation - but it's still interesting that they validated it.

https://csrc.nist.gov/Projects/Cryptographic-Algorithm-Valid...

Re: Snowden leak: Cavium networking hardware may contain NSA backdoor

#103
post #34

Earlier this year, a man was sentenced to prison for six years for stealing Ubiquiti data that the NSA also apparently can steal. https://www.justice.gov/usao-sdny/pr/former-employee-technol...

Leaving out the extortion part makes it very hard to read your comment as being made in good faith.

Re: Snowden leak: Cavium networking hardware may contain NSA backdoor

#104
post #45

Earlier quoted context omitted.

I think at this point it's pretty safe to assume that all of the well-known network hardware is compromised.

I wonder if MikroTik would be compromised- they’re Latvian and don’t necessarily have to bow to the NSA.

There's been plenty of remote 0days in MikroTik's products. At one point people were paying a pretty penny for them.

Re: Snowden leak: Cavium networking hardware may contain NSA backdoor

#106
post #6

The tweet seems to imply that the entire Ubiquiti Networks line of network hardware could be compromised. That's a shame; I was thinking of installing some in my house. I'm sure that Ubiquiti's customers will not be happy if they find out that the US Govt can access their private data.

Pretty sure only the EdgeRouter and some of the older Unifi Security Gateways use Cavium chips. Most of the newer stuff (like the Dream Machine line) I don't think are anymore. None of the Unifi APs did either I don't think (the U6 ones have Mediatek chips in them)

Annoyingly, the ER4 uses the Cavium Octeon III. I have a few of those in production.

Re: Snowden leak: Cavium networking hardware may contain NSA backdoor

#107

When I buy something electronic, my approach is "everything that is closed and goes online will be used to spy on people". It may seem a stretch, but governments can't exercise power over something they cannot control, and truly private communications would take away some of that control. To me there are no conspiracy theories or other strange reasons for being able to decrypt any seemingly private information except…

For sure, but since a state has basically unlimited resources to find vulnerabilities, I'd assume it's possible for state actors to reach a target if they are determined enough.

Might as well make it difficult though.

Re: Snowden leak: Cavium networking hardware may contain NSA backdoor

#108
post #6

The tweet seems to imply that the entire Ubiquiti Networks line of network hardware could be compromised. That's a shame; I was thinking of installing some in my house. I'm sure that Ubiquiti's customers will not be happy if they find out that the US Govt can access their private data.

I'm currently replacing my network equipment with Mikrotik, not because I believe it to be safer than Ubiquity, but because then at least it's made in the EU. But now I'm thinking: Is it better that the US is spying on me in Europe, vs. having EU governments do it? I feel like I'd be somewhat more safe from the US, compared to if my own government decides to spy on me. Maybe I should look into Chilean network equipme…

Other countries spy on you and sell it to your own country.

Re: Snowden leak: Cavium networking hardware may contain NSA backdoor

#109

When I buy something electronic, my approach is "everything that is closed and goes online will be used to spy on people". It may seem a stretch, but governments can't exercise power over something they cannot control, and truly private communications would take away some of that control. To me there are no conspiracy theories or other strange reasons for being able to decrypt any seemingly private information except…

“100% open and auditable from the operating system to the cpu” is the main goal of the Betrusted project: https://betrusted.io/

>“100% open and auditable from the operating system to the cpu” is the main goal of the Betrusted project: https://betrusted.io/

Hopefully there's a 4G version coming. This seems too good to be true.

Re: Snowden leak: Cavium networking hardware may contain NSA backdoor

#110

Very impressive work by the NSA, if true. Both from a political and technical perspective. It's good to know that our intelligence services are doing what they're supposed to, and doing it well. However, as interesting as this revelation is, it's unfortunate that Snowden decided to defect to the Russians and share his stolen cache of top secret documents with them and China, using Western journalists as ideological c…

Shilling indeed.
Post reply on HN