Live data from Hacker News

Snowden leak: Cavium networking hardware may contain NSA backdoor

twitter.com

191–200 of 628 posts

Re: Snowden leak: Cavium networking hardware may contain NSA backdoor

#191

Earlier quoted context omitted.

You can't hold it against someone that they don't want to be tortured/killed.

Nobody was going to torture or kill snowden. His risk was prison, no more.

Nobody gets tortured or killed in prison?

Regardless of your thoughts on the guy, nobody deserves what Assange has gone through in custody. Same with Manning.

Re: Snowden leak: Cavium networking hardware may contain NSA backdoor

#192
post #30
post #24

[flagged]

Huawei stuff is proven to be compromised, just not by NSA, instead by China.

It was never proven to be compromised though. GCHQ concluded after many years that they were sloppy, not malicious. All of the fear mongering by the US is what gave everyone the impression they were compromised.

Re: Snowden leak: Cavium networking hardware may contain NSA backdoor

#193
post #65
post #52

Earlier quoted context omitted.

Is there anyone here who actually thought cloud provider HSMs were secure against the provider itself or whatever nation state(s) have jurisdiction over it? It would never occur to me to even suspect that. I assume that anything I do in the cloud is absolutely transparent to the cloud provider unless it's running homomorphic encryption, which is still too slow and limited to do much that is useful. I would trust them…

If your threat model includes the nation state where you physical infrastructure is, you're hosed.

> If your threat model includes the nation state where you physical infrastructure is, you're hosed.

True. But even if you trust your nation state 100%, having a backdoor means you now have to worry about it falling into the wrong hands.

Re: Snowden leak: Cavium networking hardware may contain NSA backdoor

#195

Genuinely, at this point you should just assume 100% of your electronics are compromised by someone. If it’s not a government (yours or otherwise) then a corporation will fill the gaps (while in most cases also giving it to those governments) You should assume you have no privacy anywhere in your life.

I have a laptop with no communications functioning and I'm sure it is not compromised. The proof of it is openly stored the wallet.dat file with no any password.

Re: Snowden leak: Cavium networking hardware may contain NSA backdoor

#196
post #6

The tweet seems to imply that the entire Ubiquiti Networks line of network hardware could be compromised. That's a shame; I was thinking of installing some in my house. I'm sure that Ubiquiti's customers will not be happy if they find out that the US Govt can access their private data.

Trying to understand what crypto is the network hardware itself performing? TLS is end to end, even if you run a VPN on the router the keys were not generated there probably

Re: Snowden leak: Cavium networking hardware may contain NSA backdoor

#197
post #180
post #143

Earlier quoted context omitted.

AWS support is pretty fucking terrible generally. We’re a very high rolling enterprise customer and it’s pretty obvious that some of their shit is being managed by two guys in a shed somewhere who don’t talk to each other.

Using AWS Greengrass?

Hate Greengrass; Love joy.

Re: Snowden leak: Cavium networking hardware may contain NSA backdoor

#198
post #52

More interestingly, Cavium (now Marvell) also designed and manufactured the HSMs which are used by the top cloud providers (such as AWS, GCP, possibly Azure too), to hold the most critical private keys: https://www.prnewswire.com/news-releases/caviums-liquidsecur...

Is there anyone here who actually thought cloud provider HSMs were secure against the provider itself or whatever nation state(s) have jurisdiction over it? It would never occur to me to even suspect that. I assume that anything I do in the cloud is absolutely transparent to the cloud provider unless it's running homomorphic encryption, which is still too slow and limited to do much that is useful. I would trust them…

See the Cryptographic Control Over Data Access [0] section here for one answer to this problem.

[0] https://cloud.google.com/blog/products/identity-security/new...

Re: Snowden leak: Cavium networking hardware may contain NSA backdoor

#199

Earlier quoted context omitted.

As a general rule when criminal conspiracies are taken to task, they don't retain a right to privacy for their communications that aren't about the criminal conspiracy. Rather it all comes out in court. I understand why Snowden released the way he did, and given how it kept attention on the subject for longer than Binney/Klein it was probably the right call. But there should have also been an escrow/intent to dump th…

Do you really think the entire American IC is a "criminal conspiracy", or are you just trying to justify the fact that Snowden is an angry and vindictive sharepoint admin who simply dumped everything he had access to without regard for what was actually in those documents?

The only way they're not is by the Nixonian "when the President does it, that means it's not illegal" standard.

Re: Snowden leak: Cavium networking hardware may contain NSA backdoor

#200
post #141

On a technical level how would this work? Could it be observed by the router occasionally sending packets unsolicited to nsa.gov? [joke, obviously it wouldn't send them to a well-known address, but to some "unexpected" place] Or maybe when the router has to generate a private key [does it?] it would generate one with a flaw?

Weak or compromised RNG is enough to make most crypto algorithms brute-force-able at NSA scale.
Post reply on HN