Live data from Hacker News

Snowden leak: Cavium networking hardware may contain NSA backdoor

twitter.com

161–170 of 628 posts

Re: Snowden leak: Cavium networking hardware may contain NSA backdoor

#161

Earlier quoted context omitted.

Snowden leaked a shit ton of documents, the vast majority of which had absolutely nothing to do with any kind of NSA wrongdoing. Journalists then had to go through and try to figure out what these documents actually meant (which they frequently misunderstood). Obviously they're still doing it to today.

As a general rule when criminal conspiracies are taken to task, they don't retain a right to privacy for their communications that aren't about the criminal conspiracy. Rather it all comes out in court. I understand why Snowden released the way he did, and given how it kept attention on the subject for longer than Binney/Klein it was probably the right call. But there should have also been an escrow/intent to dump th…

Do you really think the entire American IC is a "criminal conspiracy", or are you just trying to justify the fact that Snowden is an angry and vindictive sharepoint admin who simply dumped everything he had access to without regard for what was actually in those documents?

Re: Snowden leak: Cavium networking hardware may contain NSA backdoor

#162
post #52

Earlier quoted context omitted.

Is there anyone here who actually thought cloud provider HSMs were secure against the provider itself or whatever nation state(s) have jurisdiction over it? It would never occur to me to even suspect that. I assume that anything I do in the cloud is absolutely transparent to the cloud provider unless it's running homomorphic encryption, which is still too slow and limited to do much that is useful. I would trust them…

Lots of people believe that. They believe truthfully you can get to the level of AWS, MS, Google, Facebook or Apple whilst standing up to the nations that host those companies. I've walked into government employees in the hallways of tiny ISPs, I see no reason to believe at all that larger companies are any different except for when easier backdoors have been installed.

The really concerning part is to be STILL believing that after the Snowden scandal, after everybody has seen the slides that explain in detail how the NSA sends an FBI team to gather data from (then, in 2013) Microsoft, Yahoo, Google, Facebook, PalTalk, YouTube, Skype, AOL, Apple (and Dropbox being planned).

Also how Yahoo first refused but was forced to comply by the Foreign Intelligence Surveillance Court of Review.

https://www.electrospaces.net/2014/04/what-is-known-about-ns...

(Note that supposedly, "the companies prefer installing their own monitoring capabilities to their networks and servers, instead of allowing the FBI to plug in government-controlled equipment.")

Re: Snowden leak: Cavium networking hardware may contain NSA backdoor

#163

Very impressive work by the NSA, if true. Both from a political and technical perspective. It's good to know that our intelligence services are doing what they're supposed to, and doing it well. However, as interesting as this revelation is, it's unfortunate that Snowden decided to defect to the Russians and share his stolen cache of top secret documents with them and China, using Western journalists as ideological c…

You can't hold it against someone that they don't want to be tortured/killed.

Nobody was going to torture or kill snowden. His risk was prison, no more.

Re: Snowden leak: Cavium networking hardware may contain NSA backdoor

#164
post #51

Ok the claim is the CPU was compromised and they were using ARM based tech. Is then ARM compromised? Cavium is now Marvell Technology.

> Ok the claim is the CPU was compromised and they using ARM based tech.

MIPS and ARM.

And Linux MIPS doesn't even have DEP and ASLR.

Re: Snowden leak: Cavium networking hardware may contain NSA backdoor

#165
post #6

The tweet seems to imply that the entire Ubiquiti Networks line of network hardware could be compromised. That's a shame; I was thinking of installing some in my house. I'm sure that Ubiquiti's customers will not be happy if they find out that the US Govt can access their private data.

wasn't ubiquiti totally compromised in that breach a couple of years ago?

That was an insider trying to extort the company by pretending to be an outside hacker. He then posed as a whistleblower to try and throw investigators off the trail.

Re: Snowden leak: Cavium networking hardware may contain NSA backdoor

#166
post #6

The tweet seems to imply that the entire Ubiquiti Networks line of network hardware could be compromised. That's a shame; I was thinking of installing some in my house. I'm sure that Ubiquiti's customers will not be happy if they find out that the US Govt can access their private data.

wasn't ubiquiti totally compromised in that breach a couple of years ago?

[deleted]

Re: Snowden leak: Cavium networking hardware may contain NSA backdoor

#167
post #90

Earlier quoted context omitted.

That's actually not true. It can do nothing about M of N cryptography. (That's when a key is broken up such that there are N parts, and at least M (less than N) are required to decrypt. It doesn't matter how many rubber hoses you have, one person can fully divulge or give access to their key and it's still safe.

I always giggle a little when really smart people forget thugs exist and do what they’re told. If that includes breaking the knees of M people to get what they’re after, then M pairs of knees are gonna get destroyed. This isn’t hard to understand, but it’s easy to forget our civilization hangs by a thread more often than any of us care to admit.

Any organization that is really really serious about security will obviously keep at least N-M +1 folks, along with their family, in other countries.

Which is a much much higher bar to clear for any would be rubber hose attackers.

Re: Snowden leak: Cavium networking hardware may contain NSA backdoor

#168
post #52

More interestingly, Cavium (now Marvell) also designed and manufactured the HSMs which are used by the top cloud providers (such as AWS, GCP, possibly Azure too), to hold the most critical private keys: https://www.prnewswire.com/news-releases/caviums-liquidsecur...

Is there anyone here who actually thought cloud provider HSMs were secure against the provider itself or whatever nation state(s) have jurisdiction over it? It would never occur to me to even suspect that. I assume that anything I do in the cloud is absolutely transparent to the cloud provider unless it's running homomorphic encryption, which is still too slow and limited to do much that is useful. I would trust them…

I feel the same and Snowden kinda said as much regarding phones. To assume each phone is compromised by state level actors.

Re: Snowden leak: Cavium networking hardware may contain NSA backdoor

#169

How the NSA successfully manage to prevent the Washington Post and friends from discovering and reporting on this malicious backdoor? They've been sitting on these documents for a decade. Are the journalists just that *uncurious* about the deep contents of the documents they hold exclusive access to? Was this some kind of organizational failing?

The snowden leak was huge and reverberated for weeks. There were lots of followups.

However at the time it was the more sexy things like tapping google's fibre and backdoors in cisco's kits that were more interesting. This is because the public could understand those things and therefore it sold papers.

The difference between "cisco, dell and many other leading manufacturers shipped backdoors in their kit" and "cavium the small provider you've not really heard of" is large.

Most people reading the snowden stuff will have assumed that the NSA had put in backdoors to most things.

Re: Snowden leak: Cavium networking hardware may contain NSA backdoor

#170
post #30
post #24

[flagged]

Huawei stuff is proven to be compromised, just not by NSA, instead by China.

Isn't that just the US speaking in order to get more control? How is it proven? I've never seen any evidence of that, but there has been much evidence that the US does what they blames others of doing, like this and Cisco.

At this point it seems the US is accusing others for doing bad things because that's what they themselves do.

Huawei was growing really fast, threatening both Apple and Google. Then the US said it was not safe while trying to sabotage both smart phone sales and mobile networks sales. The US pressured allied countries to not choose Huawei for 5G, and didn't let companies work with them.

Huawei was also willing to compromise by giving network operators acces to source code.

Is Huawei bad? I don't know, and I've yet to see any evidence. Does the US do exactly what they are accusing other for? Yes, that has been proven multiple times.

We live in a day where we talk about privacy and security, while giving large corporations full control over our iOS and Android devices. How useful is e.g. E2E encryption really when the os itself has a direct connection to the mothership?

Post reply on HN