Snowden leak: Cavium networking hardware may contain NSA backdoor
251–260 of 628 posts
Re: Snowden leak: Cavium networking hardware may contain NSA backdoor
#252Earlier quoted context omitted.
I mean in the end everything is people just like Logan Roy said in Succession. Cryptography or any software protections are the same. It's a great quote that is very true: > "Oh, yes... The law? The law is people. And people is politics. And I can handle of people."
“I can handle of people”? Cannot parse.
Re: Snowden leak: Cavium networking hardware may contain NSA backdoor
#253When I buy something electronic, my approach is "everything that is closed and goes online will be used to spy on people". It may seem a stretch, but governments can't exercise power over something they cannot control, and truly private communications would take away some of that control. To me there are no conspiracy theories or other strange reasons for being able to decrypt any seemingly private information except…
They're carefully watching and cataloging any communications technology they can't compromise.
Re: Snowden leak: Cavium networking hardware may contain NSA backdoor
#254If it's sold in a Western nation, the NSA has a backdoor in it, and probably everyone in the Five Eyes. If it's sold anywhere else, China has a backdoor in it.
Re: Snowden leak: Cavium networking hardware may contain NSA backdoor
#255Earlier quoted context omitted.
That's actually not true. It can do nothing about M of N cryptography. (That's when a key is broken up such that there are N parts, and at least M (less than N) are required to decrypt. It doesn't matter how many rubber hoses you have, one person can fully divulge or give access to their key and it's still safe.
Lets say for example Bob, Jon, and Tom have pieces of the key. Bob and Jon are in the US and arrested over and commanded by a court to give up the key. Tom is the holdout. The US will issue an international arrest warrant, and now Tom can never safely fly again or the plane will be diverted to the nearest US friendly airport where they will be extradited. So, yea, "safe" is very situational here.
That's the actual weak link to attack.
Re: Snowden leak: Cavium networking hardware may contain NSA backdoor
#256[flagged]
Re: Snowden leak: Cavium networking hardware may contain NSA backdoor
#257Earlier quoted context omitted.
>Law firms aren't terribly entrepreneurial. Personal injury guys are the most entrepreneurial people I know...
That's why other lawyers call them ambulance chasers. Their ethics are notoriously questionable.
Re: Snowden leak: Cavium networking hardware may contain NSA backdoor
#258More interestingly, Cavium (now Marvell) also designed and manufactured the HSMs which are used by the top cloud providers (such as AWS, GCP, possibly Azure too), to hold the most critical private keys: https://www.prnewswire.com/news-releases/caviums-liquidsecur...
Is there anyone here who actually thought cloud provider HSMs were secure against the provider itself or whatever nation state(s) have jurisdiction over it? It would never occur to me to even suspect that. I assume that anything I do in the cloud is absolutely transparent to the cloud provider unless it's running homomorphic encryption, which is still too slow and limited to do much that is useful. I would trust them…
At my Fortune 250, our threat model apparently includes -- rather conveniently and coincidentally -- everything! Well, everything they make an off-the-shelf product for, anyway. It makes new purchasing decisions easy:
"Does your product make any thing, in any way, more secure?"
"Uh... Yes?"
"You son of a bitch. We're in. Roll it out everywhere. Now."
Re: Snowden leak: Cavium networking hardware may contain NSA backdoor
#259Re: Snowden leak: Cavium networking hardware may contain NSA backdoor
#260Earlier quoted context omitted.
Is there anyone here who actually thought cloud provider HSMs were secure against the provider itself or whatever nation state(s) have jurisdiction over it? It would never occur to me to even suspect that. I assume that anything I do in the cloud is absolutely transparent to the cloud provider unless it's running homomorphic encryption, which is still too slow and limited to do much that is useful. I would trust them…
I feel the same and Snowden kinda said as much regarding phones. To assume each phone is compromised by state level actors.