Live data from Hacker News

Snowden leak: Cavium networking hardware may contain NSA backdoor

twitter.com

201–210 of 628 posts

Re: Snowden leak: Cavium networking hardware may contain NSA backdoor

#201
post #93

Why now? Looks like Snowden is being weaponized, wich might indicate that he is still part of the group he is denouncing, is he a psyop? What's the goal?

From one of Twitter replies: >... this is not new... It states in the article that this thesis from Jacob R. Appelbaum was released March 25, 2022. The only thing that makes these 'new' (?) is that electrospaces discussed September 14th https://twitter.com/vxunderground/status/1703995620250325405 Electrospaces article discussion: https://news.ycombinator.com/item?id=37562225

My question was why is it relevant today, specially after Arm going public, is the Mi6 trying to cover himself by denouncing the NSA?

Re: Snowden leak: Cavium networking hardware may contain NSA backdoor

#202
post #52

Earlier quoted context omitted.

Is there anyone here who actually thought cloud provider HSMs were secure against the provider itself or whatever nation state(s) have jurisdiction over it? It would never occur to me to even suspect that. I assume that anything I do in the cloud is absolutely transparent to the cloud provider unless it's running homomorphic encryption, which is still too slow and limited to do much that is useful. I would trust them…

Lots of people believe that. They believe truthfully you can get to the level of AWS, MS, Google, Facebook or Apple whilst standing up to the nations that host those companies. I've walked into government employees in the hallways of tiny ISPs, I see no reason to believe at all that larger companies are any different except for when easier backdoors have been installed.

I don’t know how many believe it and how much is willful ignorance. The big cloud providers make big mistakes but how many trust their organizations to do better against a nation state level actor?

The underlying architectures of our systems are not secure and much of the abstractions built on top of them make that insecurity worse, not better.

For nation state level issues, the solution likely isn’t technical, that is a game of whack-a-mole, it will take a nation deciding that digital intrusions are as or more dangerous than physical ones and to draw a line in the sand. The issue is every nation is doing it and doesn’t want to cut off their own access.

Re: Snowden leak: Cavium networking hardware may contain NSA backdoor

#203
post #90

Earlier quoted context omitted.

That's actually not true. It can do nothing about M of N cryptography. (That's when a key is broken up such that there are N parts, and at least M (less than N) are required to decrypt. It doesn't matter how many rubber hoses you have, one person can fully divulge or give access to their key and it's still safe.

I always giggle a little when really smart people forget thugs exist and do what they’re told. If that includes breaking the knees of M people to get what they’re after, then M pairs of knees are gonna get destroyed. This isn’t hard to understand, but it’s easy to forget our civilization hangs by a thread more often than any of us care to admit.

Are we deep enough in the thread for the customary reminder that each measure makes it incrementally harder to attack a system?

(Including a system of people.)

Even nation state adversaries don’t have infinite resources to allocate for all opponents.

Re: Snowden leak: Cavium networking hardware may contain NSA backdoor

#204
post #52

More interestingly, Cavium (now Marvell) also designed and manufactured the HSMs which are used by the top cloud providers (such as AWS, GCP, possibly Azure too), to hold the most critical private keys: https://www.prnewswire.com/news-releases/caviums-liquidsecur...

Is there anyone here who actually thought cloud provider HSMs were secure against the provider itself or whatever nation state(s) have jurisdiction over it? It would never occur to me to even suspect that. I assume that anything I do in the cloud is absolutely transparent to the cloud provider unless it's running homomorphic encryption, which is still too slow and limited to do much that is useful. I would trust them…

The cloud act ensures this

Re: Snowden leak: Cavium networking hardware may contain NSA backdoor

#205
post #185

When I buy something electronic, my approach is "everything that is closed and goes online will be used to spy on people". It may seem a stretch, but governments can't exercise power over something they cannot control, and truly private communications would take away some of that control. To me there are no conspiracy theories or other strange reasons for being able to decrypt any seemingly private information except…

I generally hold a similar opinion. However I have two data points that suggests back-doors are not available by default (for my government at least), but that they are aggressively bugging (or auditing, lol) devices: * When I ordered the first generation Raspberry Pi, they were stuck in the toll a long time, and when they arrived all the warranty seals were broken. Consequently I never really used them. * When I ord…

I just assume I'm not interested enough to be spied upon by randoms

> When I ordered the first generation Raspberry Pi, they were stuck in the toll a long time, and when they arrived all the warranty seals were broken. Consequently I never really used them.

If state have means to bug raspberry pi it has means to re-seal the box...

Re: Snowden leak: Cavium networking hardware may contain NSA backdoor

#206
post #6

The tweet seems to imply that the entire Ubiquiti Networks line of network hardware could be compromised. That's a shame; I was thinking of installing some in my house. I'm sure that Ubiquiti's customers will not be happy if they find out that the US Govt can access their private data.

Flashing openWRT on some boxes is probably your best bet;

Or, alternatively, treat your LAN/WiFI like public internet and don't send anything unencrypted thru it

Re: Snowden leak: Cavium networking hardware may contain NSA backdoor

#207

Earlier quoted context omitted.

You can't hold it against someone that they don't want to be tortured/killed.

Nobody was going to torture or kill snowden. His risk was prison, no more.

After Guantánamo, that's not a risk I'd like to take.

Re: Snowden leak: Cavium networking hardware may contain NSA backdoor

#208
post #6

The tweet seems to imply that the entire Ubiquiti Networks line of network hardware could be compromised. That's a shame; I was thinking of installing some in my house. I'm sure that Ubiquiti's customers will not be happy if they find out that the US Govt can access their private data.

I was also going to move to Ubiquiti but decided to go with Peplink instead based on recommendations from: https://routersecurity.org/

https://www.peplink.com/products/balance-20x/

Re: Snowden leak: Cavium networking hardware may contain NSA backdoor

#209
post #171

Earlier quoted context omitted.

Are you kidding? WaPo serves the intelligence community. >After creation of the CIA in 1947, it enjoyed direct collaboration with many U.S. news organizations. But the agency faced a major challenge in October 1977, when—soon after leaving the Washington Post—famed Watergate reporter Carl Bernstein provided an extensive exposé in Rolling Stone. Citing CIA documents, Bernstein wrote that during the previous 25 years “…

The WaPo is relentlessly pro-US and pro-'intelligence community' in its writings today, too. It's transparent. Idk how it could be missed, even without knowing the history. Just read a couple articles about contemporary whistleblowers or US involvement in the Syrian civil war or the war in Ukraine or whatever.

> It's transparent. Idk how it could be missed,

Support or criticism for the intelligence community became very partisan during Trump's campaign and presidency. Once something like this becomes partisan, the average political creature loses some degree of rationality for it. The IC becomes patriotic good guys, stalwart defenders of American democracy standing up to fascism; their past and present malfeasance goes unnoticed, forgotten, or simply ignored. This is how the WaPo's relentless pro-IC stance could be missed; they've been telling a lot of people what they want to hear and all people are less critical and suspicious of things that support their biases and prejudices.

Re: Snowden leak: Cavium networking hardware may contain NSA backdoor

#210

More interestingly, Cavium (now Marvell) also designed and manufactured the HSMs which are used by the top cloud providers (such as AWS, GCP, possibly Azure too), to hold the most critical private keys: https://www.prnewswire.com/news-releases/caviums-liquidsecur...

Not Google..

Certainly Google (and Oracle and AWS):

https://www.marvell.com/company/newsroom/marvell-enables-ent...

Post reply on HN