Live data from Hacker News

Snowden leak: Cavium networking hardware may contain NSA backdoor

twitter.com

231–240 of 628 posts

Re: Snowden leak: Cavium networking hardware may contain NSA backdoor

#231
post #19

Earlier quoted context omitted.

Maybe the moral of the story is that future snowdens should leak to selected law firms instead of selected journalists? If there's one organization designed to comb through large documents for details and understand the impacts to potential parties, it is law organizations. Put 2-3 in time competition to make cases out of the documents and it will be a scramble race for justice.

All the big leaks should be done this way The Ashley Madison leaks should have been one name a week and making it a big spectacle till this very day! Same for the Snowden leaks you can also get bigger bidders for the data by drumming up interest and suspense hackers really suck at marketing, so far.

Then your risk identifying yourself in the Ashley Madison leak. You run the risk of not getting your message out in the Snowden case. The biggest threat is future publishing which is why so many countries broke laws made up charges going after Wikileaks.

A wikileak revival scares the most powerful

Re: Snowden leak: Cavium networking hardware may contain NSA backdoor

#232
post #205
post #185

Earlier quoted context omitted.

I generally hold a similar opinion. However I have two data points that suggests back-doors are not available by default (for my government at least), but that they are aggressively bugging (or auditing, lol) devices: * When I ordered the first generation Raspberry Pi, they were stuck in the toll a long time, and when they arrived all the warranty seals were broken. Consequently I never really used them. * When I ord…

I just assume I'm not interested enough to be spied upon by randoms > When I ordered the first generation Raspberry Pi, they were stuck in the toll a long time, and when they arrived all the warranty seals were broken. Consequently I never really used them. If state have means to bug raspberry pi it has means to re-seal the box...

unless they wanted you to know and feel threatened by it

Re: Snowden leak: Cavium networking hardware may contain NSA backdoor

#233
post #225
post #215

Earlier quoted context omitted.

If I want to do some computation that should not be spied on, I can still program it in BASIC on my Sinclair ZX Spectrum. If it doesn't fit in its measly 48KB of RAM, I'm probably still safe programming it on my Commodore Amiga 500. Basically, you can only trust things manufactured before "going online" became a thing.

or you know, just don't connect your computer online.

And ensure it's not by any windows, the case HD LED doesn't blink nor does the FAN make any noise.

Re: Snowden leak: Cavium networking hardware may contain NSA backdoor

#234
post #30

Earlier quoted context omitted.

Huawei stuff is proven to be compromised, just not by NSA, instead by China.

If anything, you probably need several layers of different, non-aligned country vendors to have some Swiss cheese model security. So some Huawei stuff, somewhere, as long as it isn't only Huawei stuff.

Network designs i have seen often include this for much the same reason. A perimeter firewall is from one vendor and an internal firewall is from another. If there is a security issue with one device the other should not be effected in the same way.

Re: Snowden leak: Cavium networking hardware may contain NSA backdoor

#236
post #129
post #65

Earlier quoted context omitted.

If your threat model includes the nation state where you physical infrastructure is, you're hosed.

I mean in the end everything is people just like Logan Roy said in Succession. Cryptography or any software protections are the same. It's a great quote that is very true: > "Oh, yes... The law? The law is people. And people is politics. And I can handle of people."

“I can handle of people”? Cannot parse.

Re: Snowden leak: Cavium networking hardware may contain NSA backdoor

#237
post #52

More interestingly, Cavium (now Marvell) also designed and manufactured the HSMs which are used by the top cloud providers (such as AWS, GCP, possibly Azure too), to hold the most critical private keys: https://www.prnewswire.com/news-releases/caviums-liquidsecur...

Is there anyone here who actually thought cloud provider HSMs were secure against the provider itself or whatever nation state(s) have jurisdiction over it? It would never occur to me to even suspect that. I assume that anything I do in the cloud is absolutely transparent to the cloud provider unless it's running homomorphic encryption, which is still too slow and limited to do much that is useful. I would trust them…

Cloud HSM services have always been understood as a convenience with limited real world security, without even considering nation state threats.

Re: Snowden leak: Cavium networking hardware may contain NSA backdoor

#238
post #6

The tweet seems to imply that the entire Ubiquiti Networks line of network hardware could be compromised. That's a shame; I was thinking of installing some in my house. I'm sure that Ubiquiti's customers will not be happy if they find out that the US Govt can access their private data.

I'm currently replacing my network equipment with Mikrotik, not because I believe it to be safer than Ubiquity, but because then at least it's made in the EU. But now I'm thinking: Is it better that the US is spying on me in Europe, vs. having EU governments do it? I feel like I'd be somewhat more safe from the US, compared to if my own government decides to spy on me. Maybe I should look into Chilean network equipme…

I think in order to address this question, we need to know more about your threat model.

Are you a journalist working in a sensitive/dangerous area?

Do you often participate in discussions with dissident groups?

Do you frequently access content that is illegal in your jurisdiction?

Re: Snowden leak: Cavium networking hardware may contain NSA backdoor

#239

Earlier quoted context omitted.

That's a very specific module - one of Cavium's dozens and dozens of products. Hard to tell what it is, more information is needed.

Well, there's several Cavium devices that support the deprecated/back-doored Hash_DRBG. For example, these devices were validated for the completely appropriately named "SonicOS 6.2.5 for TZ, SM and NSA". Gotta appreciate the irony. Cavium CN7020 Hash DRBG Cavium CN7130 Hash DRBG Cavium Octeon Plus CN66XX Family Hash DRBG Cavium Octeon Plus CN68XX Family Hash DRBG I don't know if that's hardware support or just a sof…

Except Hash_DRBG is neither deprecated nor backdoored. See NIST SP 800-90A Rev. 1 section 10.1.1.1 for description of the algorithm.

Re: Snowden leak: Cavium networking hardware may contain NSA backdoor

#240
post #6

The tweet seems to imply that the entire Ubiquiti Networks line of network hardware could be compromised. That's a shame; I was thinking of installing some in my house. I'm sure that Ubiquiti's customers will not be happy if they find out that the US Govt can access their private data.

If you're not under the threat cone of nation state surveillance (like trying to exfiltrate the radar-asborbing paint formula on the F35) then I wouldn't be too concerned. "That's not the point! It's about privacy!" Sure. I'll choose it ignore the fact that our civilization is somehow still functioning in a post-nuclear world.

100% agreed. If you’re concerned about privacy, being tracked online by corporations is a bigger concern than the the NSA. If you’re the target of an NSA investigation, you’re already fucked. Changing your network equipment is not going to help.
Post reply on HN