Live data from Hacker News

Snowden leak: Cavium networking hardware may contain NSA backdoor

twitter.com

171–180 of 628 posts

Re: Snowden leak: Cavium networking hardware may contain NSA backdoor

#171

How the NSA successfully manage to prevent the Washington Post and friends from discovering and reporting on this malicious backdoor? They've been sitting on these documents for a decade. Are the journalists just that *uncurious* about the deep contents of the documents they hold exclusive access to? Was this some kind of organizational failing?

Are you kidding? WaPo serves the intelligence community. >After creation of the CIA in 1947, it enjoyed direct collaboration with many U.S. news organizations. But the agency faced a major challenge in October 1977, when—soon after leaving the Washington Post—famed Watergate reporter Carl Bernstein provided an extensive exposé in Rolling Stone. Citing CIA documents, Bernstein wrote that during the previous 25 years “…

The WaPo is relentlessly pro-US and pro-'intelligence community' in its writings today, too. It's transparent. Idk how it could be missed, even without knowing the history. Just read a couple articles about contemporary whistleblowers or US involvement in the Syrian civil war or the war in Ukraine or whatever.

Re: Snowden leak: Cavium networking hardware may contain NSA backdoor

#172

How the NSA successfully manage to prevent the Washington Post and friends from discovering and reporting on this malicious backdoor? They've been sitting on these documents for a decade. Are the journalists just that *uncurious* about the deep contents of the documents they hold exclusive access to? Was this some kind of organizational failing?

WaPo, NYT, et. al. are tied to DOD and the intel community. They are the anonymous sources that provide many of their story ideas as well as quotes and sourcing. That doesn't come for free.

Re: Snowden leak: Cavium networking hardware may contain NSA backdoor

#173

So in real life terms, what does this mean for people that own USG3s? If you're so inclined, replace it? Or not use the VPN feature in the Unifi admin console? Personally, I just forward all WireGuard traffic to another computer on my network and use https://github.com/burghardt/easy-wg-quick to setup a simple VPN.

We don’t know which types of Cavium products may have vulnerabilities, which models or what the nature of it is (could be only applicable to certain features, sounds like possibly related to VPN acceleration).

So absolutely no way to know whether anything needs to be done or not, unless you expect you’re at risk of a nation state actor having a reason to specifically target you, in which case it’d be wise to stop using it.

Re: Snowden leak: Cavium networking hardware may contain NSA backdoor

#174
post #90

Earlier quoted context omitted.

That's actually not true. It can do nothing about M of N cryptography. (That's when a key is broken up such that there are N parts, and at least M (less than N) are required to decrypt. It doesn't matter how many rubber hoses you have, one person can fully divulge or give access to their key and it's still safe.

I always giggle a little when really smart people forget thugs exist and do what they’re told. If that includes breaking the knees of M people to get what they’re after, then M pairs of knees are gonna get destroyed. This isn’t hard to understand, but it’s easy to forget our civilization hangs by a thread more often than any of us care to admit.

I think you can probably get away with only breaking one pair of knees and sending a video of it to the other people.

Re: Snowden leak: Cavium networking hardware may contain NSA backdoor

#175
post #143

Earlier quoted context omitted.

We've had other issues with our CloudHSM instance, especially with the PKCS1.5 deprecation on January 1. And their support has been pretty dismal. Not expecting much from them at this point.

AWS support is pretty fucking terrible generally. We’re a very high rolling enterprise customer and it’s pretty obvious that some of their shit is being managed by two guys in a shed somewhere who don’t talk to each other.

Another satisfied user of AWS Glue, I see. On a scale of 10 to “I have no mouth and I must scream” how much do you hate their error messages?

Re: Snowden leak: Cavium networking hardware may contain NSA backdoor

#176

Earlier quoted context omitted.

As a general rule when criminal conspiracies are taken to task, they don't retain a right to privacy for their communications that aren't about the criminal conspiracy. Rather it all comes out in court. I understand why Snowden released the way he did, and given how it kept attention on the subject for longer than Binney/Klein it was probably the right call. But there should have also been an escrow/intent to dump th…

Do you really think the entire American IC is a "criminal conspiracy", or are you just trying to justify the fact that Snowden is an angry and vindictive sharepoint admin who simply dumped everything he had access to without regard for what was actually in those documents?

Yes. By the straightforward standards that non-governmental criminal conspiracies are prosecuted, a large chunk of the NSA is engaged in a criminal conspiracy. We don't hold back on prosecuting other criminal conspiracies just because their associations produce other results like financially supporting their communities and coaching their kids' soccer teams.

Re: Snowden leak: Cavium networking hardware may contain NSA backdoor

#177

Earlier quoted context omitted.

Lots of people believe that. They believe truthfully you can get to the level of AWS, MS, Google, Facebook or Apple whilst standing up to the nations that host those companies. I've walked into government employees in the hallways of tiny ISPs, I see no reason to believe at all that larger companies are any different except for when easier backdoors have been installed.

I always just tell people to lookup “Lavabit” to learn everything you need to know.

To save others a goog: https://en.wikipedia.org/wiki/Lavabit

> Lavabit is an open-source encrypted webmail service, founded in 2004. The service suspended its operations on August 8, 2013 after the U.S. Federal Government ordered it to turn over its Secure Sockets Layer (SSL) private keys, in order to allow the government to spy on Edward Snowden's email

Re: Snowden leak: Cavium networking hardware may contain NSA backdoor

#178

How the NSA successfully manage to prevent the Washington Post and friends from discovering and reporting on this malicious backdoor? They've been sitting on these documents for a decade. Are the journalists just that *uncurious* about the deep contents of the documents they hold exclusive access to? Was this some kind of organizational failing?

Are you kidding? WaPo serves the intelligence community. >After creation of the CIA in 1947, it enjoyed direct collaboration with many U.S. news organizations. But the agency faced a major challenge in October 1977, when—soon after leaving the Washington Post—famed Watergate reporter Carl Bernstein provided an extensive exposé in Rolling Stone. Citing CIA documents, Bernstein wrote that during the previous 25 years “…

There was also a German ex-journalist (dr. Udo Ulfkotte) who wrote a book about how journalists (in Germany and EU I suppose) are “bought” by intelligence agencies like the CIA:

https://www.amazon.in/Journalists-Hire-How-Buys-News/dp/1944...

Re: Snowden leak: Cavium networking hardware may contain NSA backdoor

#179

More interestingly, Cavium (now Marvell) also designed and manufactured the HSMs which are used by the top cloud providers (such as AWS, GCP, possibly Azure too), to hold the most critical private keys: https://www.prnewswire.com/news-releases/caviums-liquidsecur...

Not Google..

Re: Snowden leak: Cavium networking hardware may contain NSA backdoor

#180
post #143

Earlier quoted context omitted.

We've had other issues with our CloudHSM instance, especially with the PKCS1.5 deprecation on January 1. And their support has been pretty dismal. Not expecting much from them at this point.

AWS support is pretty fucking terrible generally. We’re a very high rolling enterprise customer and it’s pretty obvious that some of their shit is being managed by two guys in a shed somewhere who don’t talk to each other.

Using AWS Greengrass?
Post reply on HN