Live data from Hacker News

Snowden leak: Cavium networking hardware may contain NSA backdoor

twitter.com

151–160 of 628 posts

Re: Snowden leak: Cavium networking hardware may contain NSA backdoor

#151

Very impressive work by the NSA, if true. Both from a political and technical perspective. It's good to know that our intelligence services are doing what they're supposed to, and doing it well. However, as interesting as this revelation is, it's unfortunate that Snowden decided to defect to the Russians and share his stolen cache of top secret documents with them and China, using Western journalists as ideological c…

Being stranded in Moscow because the State Department cancels your passport while you're en route to Ecuador = "defection"? Cute.

Re: Snowden leak: Cavium networking hardware may contain NSA backdoor

#152
Genuinely, at this point you should just assume 100% of your electronics are compromised by someone. If it’s not a government (yours or otherwise) then a corporation will fill the gaps (while in most cases also giving it to those governments)

You should assume you have no privacy anywhere in your life.

Re: Snowden leak: Cavium networking hardware may contain NSA backdoor

#153
post #90

Earlier quoted context omitted.

That's actually not true. It can do nothing about M of N cryptography. (That's when a key is broken up such that there are N parts, and at least M (less than N) are required to decrypt. It doesn't matter how many rubber hoses you have, one person can fully divulge or give access to their key and it's still safe.

I always giggle a little when really smart people forget thugs exist and do what they’re told. If that includes breaking the knees of M people to get what they’re after, then M pairs of knees are gonna get destroyed. This isn’t hard to understand, but it’s easy to forget our civilization hangs by a thread more often than any of us care to admit.

That’s hyperbole

Re: Snowden leak: Cavium networking hardware may contain NSA backdoor

#154
post #90
post #70

Earlier quoted context omitted.

Literally hosed. There's a funny jargon term "rubber hose cryptography" that's used to refer to the cryptanalysis method where you beat someone with a rubber hose until they give you the key. It's 100% effective against all forms of cryptography including even post-quantum algorithms.

That's actually not true. It can do nothing about M of N cryptography. (That's when a key is broken up such that there are N parts, and at least M (less than N) are required to decrypt. It doesn't matter how many rubber hoses you have, one person can fully divulge or give access to their key and it's still safe.

This probably works if each person has a cyanide+happy drug pill or a grenade and is willing to sacrifice themselves and the rubber-hoser(s). I think that requires a rare level of devotion. This process must also disable a simple and fragile signalling device to let the others know what's coming.

Re: Snowden leak: Cavium networking hardware may contain NSA backdoor

#155

When I buy something electronic, my approach is "everything that is closed and goes online will be used to spy on people". It may seem a stretch, but governments can't exercise power over something they cannot control, and truly private communications would take away some of that control. To me there are no conspiracy theories or other strange reasons for being able to decrypt any seemingly private information except…

This is the right approach IMO.

Just assume you’re being persistently surveilled - if you use a computer or electronics then the likelihood approaches 100% over your lifetime.

Re: Snowden leak: Cavium networking hardware may contain NSA backdoor

#156
post #106

Earlier quoted context omitted.

Pretty sure only the EdgeRouter and some of the older Unifi Security Gateways use Cavium chips. Most of the newer stuff (like the Dream Machine line) I don't think are anymore. None of the Unifi APs did either I don't think (the U6 ones have Mediatek chips in them)

Annoyingly, the ER4 uses the Cavium Octeon III. I have a few of those in production.

Yeah, I have one at home too, so I really want more detail on what the exploit is (I wonder if if is perhaps IPSEC specific, like an RNG flaw since they talk about VPN and encryption appliances, or it could be something to do with Cavium HSMs and unrelated to the network processors).

Re: Snowden leak: Cavium networking hardware may contain NSA backdoor

#157

Earlier quoted context omitted.

It's quite a bit more subtle than that. News organization have their sources that are in the intelligence community. They use each other. Sometimes the journalist wants to use their sources for information. Other times their sources feed them disinformation disguised as information. Other times they want a back channel to leak some real information but can't be seem as coming from a government source. Being a good jo…

I have no sources at hand, but I understood the FBI/CIA is embedded within every major news org in the US.

The twitter files showed government agencies were coercing Twitter into suppressing information. I would find it hard to believe they don't also coerce at newspapers, particularly with the cozy relationship they already have with "anonymous sources" from said agencies.

Re: Snowden leak: Cavium networking hardware may contain NSA backdoor

#159
So in real life terms, what does this mean for people that own USG3s? If you're so inclined, replace it? Or not use the VPN feature in the Unifi admin console?

Personally, I just forward all WireGuard traffic to another computer on my network and use https://github.com/burghardt/easy-wg-quick to setup a simple VPN.

Post reply on HN