Earlier quoted context omitted.
That's actually not true. It can do nothing about M of N cryptography. (That's when a key is broken up such that there are N parts, and at least M (less than N) are required to decrypt. It doesn't matter how many rubber hoses you have, one person can fully divulge or give access to their key and it's still safe.
I always giggle a little when really smart people forget thugs exist and do what they’re told. If that includes breaking the knees of M people to get what they’re after, then M pairs of knees are gonna get destroyed. This isn’t hard to understand, but it’s easy to forget our civilization hangs by a thread more often than any of us care to admit.
Snowden leak: Cavium networking hardware may contain NSA backdoor
221–230 of 628 posts
Re: Snowden leak: Cavium networking hardware may contain NSA backdoor
#222So in real life terms, what does this mean for people that own USG3s? If you're so inclined, replace it? Or not use the VPN feature in the Unifi admin console? Personally, I just forward all WireGuard traffic to another computer on my network and use https://github.com/burghardt/easy-wg-quick to setup a simple VPN.
It's another thing when it comes to resisting surveillance capitalism :
https://web.archive.org/web/20180919021829/https://www.alexr...
It's completely disproportionate that Hollywood is making people lose control of their own computers because they are worried about copyright infringement !!
That a boycott of Intel and Ryzen CPUs, "Trusted" Platform Modules, and Windows (8+) also probably makes the job of NSA/CIA/FBI harder (because they have likely backdoored them) is just a bonus.
(Of course there's also a potential failure mode that some much more hostile actors might get their hands on some of these backdoors, but it doesn't seem worth worrying about it until we get a high profile example of that happening ?)
Of course if you have the responsibility of, say, protecting your non-US company from industrial espionage, the situation is very different.
Re: Snowden leak: Cavium networking hardware may contain NSA backdoor
#223The tweet seems to imply that the entire Ubiquiti Networks line of network hardware could be compromised. That's a shame; I was thinking of installing some in my house. I'm sure that Ubiquiti's customers will not be happy if they find out that the US Govt can access their private data.
I'm currently replacing my network equipment with Mikrotik, not because I believe it to be safer than Ubiquity, but because then at least it's made in the EU. But now I'm thinking: Is it better that the US is spying on me in Europe, vs. having EU governments do it? I feel like I'd be somewhat more safe from the US, compared to if my own government decides to spy on me. Maybe I should look into Chilean network equipme…
https://en.wikipedia.org/wiki/Five_Eyes
> In recent years, documents of the FVEY have shown that they are intentionally spying on one another's citizens and sharing the collected information with each other, although the FVEYs countries claim that all intelligence sharing was done legally, according to the domestic law of the respective nations.
So in practice, it's entirely irrelevant: your data will end up Hoovered up by someone, coated with a veneer of legality, and provided back to your government to act on (or not).
Don't be too interesting to your government, I guess?
Re: Snowden leak: Cavium networking hardware may contain NSA backdoor
#224An interesting question I'd like answered: Are the TPM 2.0 modules that Microsoft is requiring for Windows 11 installs similarly backdoored?
https://www.theverge.com/2013/6/6/4403868/nsa-fbi-mine-data-...
I think it's a safe assumption that all American microprocessors have backdoors.
What does this mean for OpSec? If I am a dissident (or garden-variety cyber criminal), how do I evade my online activities being tracked by a sufficiently determined team at the NSA? We've known (or have assumed to know) for years that CPUs produced by AMD, Intel, and Apple have backdoors. If my machine lacks any personally identifying information, only interacts through the internet through a network device that uses a VPN and encrypted tunneling, then I should be fine in spite of CPU/OS backdoors. However, using a VPN with encrypted tunneling doesn't seem to be enough if my router also has a backdoor, and the data or encryption keys can be intercepted and tied to the personal information I've given my ISP.
Where do we go from here? Do I need a Loongson-based PC and a Chinese router on top of an encrypted VPN? Obviously we have to assume that these are all backdoored as well, but that shouldn't matter as my activities don't likely won't make me a target of the PRC.
Re: Snowden leak: Cavium networking hardware may contain NSA backdoor
#225When I buy something electronic, my approach is "everything that is closed and goes online will be used to spy on people". It may seem a stretch, but governments can't exercise power over something they cannot control, and truly private communications would take away some of that control. To me there are no conspiracy theories or other strange reasons for being able to decrypt any seemingly private information except…
If I want to do some computation that should not be spied on, I can still program it in BASIC on my Sinclair ZX Spectrum. If it doesn't fit in its measly 48KB of RAM, I'm probably still safe programming it on my Commodore Amiga 500. Basically, you can only trust things manufactured before "going online" became a thing.
Re: Snowden leak: Cavium networking hardware may contain NSA backdoor
#226Earlier quoted context omitted.
Youtube would delist that before they could all see it though.
You know there are other ways to have a video and send it to people than YouTube, right? You can just email a link from dropbox or gdrive, or an attachment, or send a WhatsApp/Telegram/etc. message, send a letter with a USB drive, etc.
Re: Snowden leak: Cavium networking hardware may contain NSA backdoor
#227On a technical level how would this work? Could it be observed by the router occasionally sending packets unsolicited to nsa.gov? [joke, obviously it wouldn't send them to a well-known address, but to some "unexpected" place] Or maybe when the router has to generate a private key [does it?] it would generate one with a flaw?
Re: Snowden leak: Cavium networking hardware may contain NSA backdoor
#228Re: Snowden leak: Cavium networking hardware may contain NSA backdoor
#229Earlier quoted context omitted.
From one of Twitter replies: >... this is not new... It states in the article that this thesis from Jacob R. Appelbaum was released March 25, 2022. The only thing that makes these 'new' (?) is that electrospaces discussed September 14th https://twitter.com/vxunderground/status/1703995620250325405 Electrospaces article discussion: https://news.ycombinator.com/item?id=37562225
My question was why is it relevant today, specially after Arm going public, is the Mi6 trying to cover himself by denouncing the NSA?
Re: Snowden leak: Cavium networking hardware may contain NSA backdoor
#230Earlier quoted context omitted.
We've had other issues with our CloudHSM instance, especially with the PKCS1.5 deprecation on January 1. And their support has been pretty dismal. Not expecting much from them at this point.
AWS support is pretty fucking terrible generally. We’re a very high rolling enterprise customer and it’s pretty obvious that some of their shit is being managed by two guys in a shed somewhere who don’t talk to each other.