Live data from Hacker News

Snowden leak: Cavium networking hardware may contain NSA backdoor

twitter.com

211–220 of 628 posts

Re: Snowden leak: Cavium networking hardware may contain NSA backdoor

#211

Earlier quoted context omitted.

Lots of people believe that. They believe truthfully you can get to the level of AWS, MS, Google, Facebook or Apple whilst standing up to the nations that host those companies. I've walked into government employees in the hallways of tiny ISPs, I see no reason to believe at all that larger companies are any different except for when easier backdoors have been installed.

The really concerning part is to be STILL believing that after the Snowden scandal, after everybody has seen the slides that explain in detail how the NSA sends an FBI team to gather data from (then, in 2013) Microsoft, Yahoo, Google, Facebook, PalTalk, YouTube, Skype, AOL, Apple (and Dropbox being planned). Also how Yahoo first refused but was forced to comply by the Foreign Intelligence Surveillance Court of Review…

And for Yahoo this was reason why Alex Stamos resign: https://arstechnica.com/tech-policy/2016/10/report-fbi-andor...

Re: Snowden leak: Cavium networking hardware may contain NSA backdoor

#212
post #205
post #185

Earlier quoted context omitted.

I generally hold a similar opinion. However I have two data points that suggests back-doors are not available by default (for my government at least), but that they are aggressively bugging (or auditing, lol) devices: * When I ordered the first generation Raspberry Pi, they were stuck in the toll a long time, and when they arrived all the warranty seals were broken. Consequently I never really used them. * When I ord…

I just assume I'm not interested enough to be spied upon by randoms > When I ordered the first generation Raspberry Pi, they were stuck in the toll a long time, and when they arrived all the warranty seals were broken. Consequently I never really used them. If state have means to bug raspberry pi it has means to re-seal the box...

> If state have means to bug raspberry pi it has means to re-seal the box...

That's a good point that I never made sense of. The most likely explanation is simply an oversealouz toll agent. It just left a bad taste in my mouth so I didn't want to play with them...

I had largely forgotten about it until the Google Pixel got stuck.

Re: Snowden leak: Cavium networking hardware may contain NSA backdoor

#213
post #70
post #65

Earlier quoted context omitted.

If your threat model includes the nation state where you physical infrastructure is, you're hosed.

Literally hosed. There's a funny jargon term "rubber hose cryptography" that's used to refer to the cryptanalysis method where you beat someone with a rubber hose until they give you the key. It's 100% effective against all forms of cryptography including even post-quantum algorithms.

You would be surprised that for a percent this would not work. Some even like it. Some have a deathwish and want to be a martyr. Some people blow themselves up to further a cause. Also put under heavy stress memories of keys cannot be recalled at times.

It's probably slightly less effective than threatening to kill family members but probably more than threat of jail time.

Either way you require someone alive and with mental awareness. The mind reading tools found in science fiction hasn't been developed yet.

Re: Snowden leak: Cavium networking hardware may contain NSA backdoor

#214

Earlier quoted context omitted.

Snowden leaked a shit ton of documents, the vast majority of which had absolutely nothing to do with any kind of NSA wrongdoing. Journalists then had to go through and try to figure out what these documents actually meant (which they frequently misunderstood). Obviously they're still doing it to today.

As a general rule when criminal conspiracies are taken to task, they don't retain a right to privacy for their communications that aren't about the criminal conspiracy. Rather it all comes out in court. I understand why Snowden released the way he did, and given how it kept attention on the subject for longer than Binney/Klein it was probably the right call. But there should have also been an escrow/intent to dump th…

>As a general rule when criminal conspiracies are taken to task, they don't retain a right to privacy for their communications that aren't about the criminal conspiracy. Rather it all comes out in court.

That doesn't seem to be true. There are many court cases involving criminal conspiracies where you cannot find unrelated information about the involved people.

Re: Snowden leak: Cavium networking hardware may contain NSA backdoor

#215

When I buy something electronic, my approach is "everything that is closed and goes online will be used to spy on people". It may seem a stretch, but governments can't exercise power over something they cannot control, and truly private communications would take away some of that control. To me there are no conspiracy theories or other strange reasons for being able to decrypt any seemingly private information except…

If I want to do some computation that should not be spied on, I can still program it in BASIC on my Sinclair ZX Spectrum. If it doesn't fit in its measly 48KB of RAM, I'm probably still safe programming it on my Commodore Amiga 500.

Basically, you can only trust things manufactured before "going online" became a thing.

Re: Snowden leak: Cavium networking hardware may contain NSA backdoor

#216
post #52

More interestingly, Cavium (now Marvell) also designed and manufactured the HSMs which are used by the top cloud providers (such as AWS, GCP, possibly Azure too), to hold the most critical private keys: https://www.prnewswire.com/news-releases/caviums-liquidsecur...

Is there anyone here who actually thought cloud provider HSMs were secure against the provider itself or whatever nation state(s) have jurisdiction over it? It would never occur to me to even suspect that. I assume that anything I do in the cloud is absolutely transparent to the cloud provider unless it's running homomorphic encryption, which is still too slow and limited to do much that is useful. I would trust them…

I think there’s such a thing as plausible deniability here. We didn’t know for certain so we weren’t culpable, but now that it’s public record, we really have to do something about it or risk liability with our customer data.

Re: Snowden leak: Cavium networking hardware may contain NSA backdoor

#217

When I buy something electronic, my approach is "everything that is closed and goes online will be used to spy on people". It may seem a stretch, but governments can't exercise power over something they cannot control, and truly private communications would take away some of that control. To me there are no conspiracy theories or other strange reasons for being able to decrypt any seemingly private information except…

"If it's technically possible, they're doing it."

It's their job.

Re: Snowden leak: Cavium networking hardware may contain NSA backdoor

#218
The intelligence agency enjoyed a supremely underserved SURGE in popularity during the Trump era because they were seen as an enemy of Trump.

Let's all get back to reality now. They LIE and influence US politics to preserve their operations (not political, it's self-preservation).

If you see something like "100 former intelligence agents sign letter saying ..." then run, RUN!

Re: Snowden leak: Cavium networking hardware may contain NSA backdoor

#219

How the NSA successfully manage to prevent the Washington Post and friends from discovering and reporting on this malicious backdoor? They've been sitting on these documents for a decade. Are the journalists just that *uncurious* about the deep contents of the documents they hold exclusive access to? Was this some kind of organizational failing?

I suspect when a trove of documents is big enough, newspaper readers lose interest before you run out of documents. I mean, even on this tech forum hardly anyone knows who Cavium are, let alone your average Washington Post reader.

> newspaper readers lose interest before you run out of documents

So.. what's your case here? It would be so expensive to host and publish the documents that they would be unable to recoup their investment based upon lack of interest?

> hardly anyone knows who Cavium are, let alone your average Washington Post reader.

Oh.. I don't know.. maybe that's because no one has reported on it and explained why it would be important?

There's a lot of circular reasoning present to create excuses for an entity that really doesn't need or deserve it.

Re: Snowden leak: Cavium networking hardware may contain NSA backdoor

#220

Earlier quoted context omitted.

I think you can probably get away with only breaking one pair of knees and sending a video of it to the other people.

Youtube would delist that before they could all see it though.

You know there are other ways to have a video and send it to people than YouTube, right? You can just email a link from dropbox or gdrive, or an attachment, or send a WhatsApp/Telegram/etc. message, send a letter with a USB drive, etc.
Post reply on HN