Live data from Hacker News

Snowden leak: Cavium networking hardware may contain NSA backdoor

twitter.com

241–250 of 628 posts

Re: Snowden leak: Cavium networking hardware may contain NSA backdoor

#241
post #231

Earlier quoted context omitted.

All the big leaks should be done this way The Ashley Madison leaks should have been one name a week and making it a big spectacle till this very day! Same for the Snowden leaks you can also get bigger bidders for the data by drumming up interest and suspense hackers really suck at marketing, so far.

Then your risk identifying yourself in the Ashley Madison leak. You run the risk of not getting your message out in the Snowden case. The biggest threat is future publishing which is why so many countries broke laws made up charges going after Wikileaks. A wikileak revival scares the most powerful

It would also be allot of fun

Re: Snowden leak: Cavium networking hardware may contain NSA backdoor

#242

Very impressive work by the NSA, if true. Both from a political and technical perspective. It's good to know that our intelligence services are doing what they're supposed to, and doing it well. However, as interesting as this revelation is, it's unfortunate that Snowden decided to defect to the Russians and share his stolen cache of top secret documents with them and China, using Western journalists as ideological c…

Being stranded in Moscow because the State Department cancels your passport while you're en route to Ecuador = "defection"? Cute.

I doubt Russia cared much about a cancelled US passport. If they felt he was not worth something to them they would have made sure he was out of Russia.

Personally I don't think it was intentional on his part to get stuck in Russia, just a bad error. But he is certainly living there by their "good will" now, and it shows in his public behaviour.

Re: Snowden leak: Cavium networking hardware may contain NSA backdoor

#243
Is this only limited to “USG” products? Or safe to assume UDM also impacted?

edit: FUCK

“ Quad-core ARM® Cortex®-A57 at 1.7 GHz”

https://store.ui.com/us/en/pro/category/all-unifi-gateway-co...

People paying premium $$$ for this. UI better redesign and compensate users.

Re: Snowden leak: Cavium networking hardware may contain NSA backdoor

#244
post #65
post #52

Earlier quoted context omitted.

Is there anyone here who actually thought cloud provider HSMs were secure against the provider itself or whatever nation state(s) have jurisdiction over it? It would never occur to me to even suspect that. I assume that anything I do in the cloud is absolutely transparent to the cloud provider unless it's running homomorphic encryption, which is still too slow and limited to do much that is useful. I would trust them…

If your threat model includes the nation state where you physical infrastructure is, you're hosed.

Addendum: if your threat model includes any nation state that has significant ties to the nation state that hosts your physical or transit infrastructure, you're hosed.

Re: Snowden leak: Cavium networking hardware may contain NSA backdoor

#245
post #30

Earlier quoted context omitted.

Huawei stuff is proven to be compromised, just not by NSA, instead by China.

If anything, you probably need several layers of different, non-aligned country vendors to have some Swiss cheese model security. So some Huawei stuff, somewhere, as long as it isn't only Huawei stuff.

checkpoint firewall (Israel), PAN/fortinet firewall (US), and huawei firewall (china) daisy chained - should keep each other in sync and provide defense in depth :D

Re: Snowden leak: Cavium networking hardware may contain NSA backdoor

#246
post #53

Earlier quoted context omitted.

It’s happened at least three times. They got Yahoo’s CEO to [bypass SOX compliance and] hand over access to 500 million email accounts. Last I heard, she said they convinced her she wasn’t allowed to ask corporate lawyers for guidance. https://www.theguardian.com/technology/2016/oct/04/yahoo-sec... Both she and Yahoo’s shareholders suffered greatly for complying. There’s also Crypto AG, which was a foreign-owned CIA…

> Last I heard, she said they convinced her she wasn’t allowed to ask corporate lawyers for guidance. To me, anyone purporting to be an official government employee advising you that you cannot speak to an attorney throws up so many red flags, that I just can't imagine it being anything but sinister.

If an official government employee is already apparently breaking the law and also threatening you personally, you need to ask yourself whether they'll worry about continuing to break the law in order to make good on their threats.

Note that none of the people that coerced Mayer into breaking the law have been disciplined or even named, so I guess they didn't need to worry about such things after all.

I've heard EFF and corporate lawyers advise people to never speak to law enforcement under any circumstances. The reason is that the police are allowed to lie about their intentions and the facts of the case, and if you say something that is incorrect, you can be prosecuted for lying to them.

So, for example, they can spew a bunch of lies and trick you into incorrectly speculating ("Since Jim was waving that gun at you, then I guess he really did buy it after all"), and then later, you need to prove (probably without the benefit of a recording) that it should have been clear to the officers that it was just speculation, or you go to jail.

Their advice boiled down to politely and repeatedly respond with "I want my lawyer". At least one court has ruled that failing to respond at all to a question (even after repeatedly asking for a lawyer) means that you're now responding (perhaps with body language) and the interrogation is therefore admissible.

Re: Snowden leak: Cavium networking hardware may contain NSA backdoor

#247

Earlier quoted context omitted.

Not Google..

Certainly Google (and Oracle and AWS): https://www.marvell.com/company/newsroom/marvell-enables-ent...

I'm not saying you are wrong but I can make a website which claims some cloud provider uses my hardware too. Their website is irrelevant. Do we have a Google (or AWS/...) page regarding this?

Re: Snowden leak: Cavium networking hardware may contain NSA backdoor

#248

Very impressive work by the NSA, if true. Both from a political and technical perspective. It's good to know that our intelligence services are doing what they're supposed to, and doing it well. However, as interesting as this revelation is, it's unfortunate that Snowden decided to defect to the Russians and share his stolen cache of top secret documents with them and China, using Western journalists as ideological c…

This is the thing that rubs me the wrong way about Snowden - had he stayed and faced the music as a true whistleblower, he would've earned my respect for sticking to principles and acting as a loyal citizen acting in the interest of the country, even in the face of persecution.

He did not do that. Instead, he's living a comfortable life in the bowels of a country that is committing vicious, daily war crimes. I don't hear him make a peep about kidnapped Ukrainian children, or the civilians that Russia tortures and kills. He's not a principled activist who's suffering for the cause of freedom at any cost, he's now just a loyal Russian citizen who opportunistically committed a massive act of espionage a long time ago.

Re: Snowden leak: Cavium networking hardware may contain NSA backdoor

#249
post #65

Earlier quoted context omitted.

If your threat model includes the nation state where you physical infrastructure is, you're hosed.

Addendum: if your threat model includes any nation state that has significant ties to the nation state that hosts your physical or transit infrastructure, you're hosed.

How might this apply or what are the implications of Signal given its US jurisdiction?

Re: Snowden leak: Cavium networking hardware may contain NSA backdoor

#250

When I buy something electronic, my approach is "everything that is closed and goes online will be used to spy on people". It may seem a stretch, but governments can't exercise power over something they cannot control, and truly private communications would take away some of that control. To me there are no conspiracy theories or other strange reasons for being able to decrypt any seemingly private information except…

This is the right approach IMO. Just assume you’re being persistently surveilled - if you use a computer or electronics then the likelihood approaches 100% over your lifetime.

If you have to take this approach they have already won
Post reply on HN