Live data from Hacker News

Snowden leak: Cavium networking hardware may contain NSA backdoor

twitter.com

251–260 of 628 posts

Re: Snowden leak: Cavium networking hardware may contain NSA backdoor

#252
post #236
post #129

Earlier quoted context omitted.

I mean in the end everything is people just like Logan Roy said in Succession. Cryptography or any software protections are the same. It's a great quote that is very true: > "Oh, yes... The law? The law is people. And people is politics. And I can handle of people."

“I can handle of people”? Cannot parse.

I think that was a mobile typo. The quote is just "I can handle people"

Re: Snowden leak: Cavium networking hardware may contain NSA backdoor

#253

When I buy something electronic, my approach is "everything that is closed and goes online will be used to spy on people". It may seem a stretch, but governments can't exercise power over something they cannot control, and truly private communications would take away some of that control. To me there are no conspiracy theories or other strange reasons for being able to decrypt any seemingly private information except…

It's clear that they feel that way also. The engineer Andreas Spiess recently appeared in a briefing on dangerous, anarchy-enabling technologies simply for making a youtube video on an encrypted messaging protocol over lora mesh networking.

They're carefully watching and cataloging any communications technology they can't compromise.

Re: Snowden leak: Cavium networking hardware may contain NSA backdoor

#255
post #125
post #90

Earlier quoted context omitted.

That's actually not true. It can do nothing about M of N cryptography. (That's when a key is broken up such that there are N parts, and at least M (less than N) are required to decrypt. It doesn't matter how many rubber hoses you have, one person can fully divulge or give access to their key and it's still safe.

Lets say for example Bob, Jon, and Tom have pieces of the key. Bob and Jon are in the US and arrested over and commanded by a court to give up the key. Tom is the holdout. The US will issue an international arrest warrant, and now Tom can never safely fly again or the plane will be diverted to the nearest US friendly airport where they will be extradited. So, yea, "safe" is very situational here.

Doesn't Tom's key fragment have to be on a disk somewhere for things to work?

That's the actual weak link to attack.

Re: Snowden leak: Cavium networking hardware may contain NSA backdoor

#257
post #56

Earlier quoted context omitted.

>Law firms aren't terribly entrepreneurial. Personal injury guys are the most entrepreneurial people I know...

That's why other lawyers call them ambulance chasers. Their ethics are notoriously questionable.

More importantly, there's money out the other end for them. The payoff is more questionable for information from Snowden leaks. Yes, I guess a journalistic outlet can get a big scoop and that drives eyeballs which leads to advertisers... But that's pretty different from the ambulance-chaser payout.

Re: Snowden leak: Cavium networking hardware may contain NSA backdoor

#258
post #52

More interestingly, Cavium (now Marvell) also designed and manufactured the HSMs which are used by the top cloud providers (such as AWS, GCP, possibly Azure too), to hold the most critical private keys: https://www.prnewswire.com/news-releases/caviums-liquidsecur...

Is there anyone here who actually thought cloud provider HSMs were secure against the provider itself or whatever nation state(s) have jurisdiction over it? It would never occur to me to even suspect that. I assume that anything I do in the cloud is absolutely transparent to the cloud provider unless it's running homomorphic encryption, which is still too slow and limited to do much that is useful. I would trust them…

> If your threat model includes...

At my Fortune 250, our threat model apparently includes -- rather conveniently and coincidentally -- everything! Well, everything they make an off-the-shelf product for, anyway. It makes new purchasing decisions easy:

"Does your product make any thing, in any way, more secure?"

"Uh... Yes?"

"You son of a bitch. We're in. Roll it out everywhere. Now."

Re: Snowden leak: Cavium networking hardware may contain NSA backdoor

#259
post #105
post #30

Earlier quoted context omitted.

Huawei stuff is proven to be compromised, just not by NSA, instead by China.

China is way less dangerous to me than the NSA

How is the NSA personally dangerous to you?

Re: Snowden leak: Cavium networking hardware may contain NSA backdoor

#260
post #168
post #52

Earlier quoted context omitted.

Is there anyone here who actually thought cloud provider HSMs were secure against the provider itself or whatever nation state(s) have jurisdiction over it? It would never occur to me to even suspect that. I assume that anything I do in the cloud is absolutely transparent to the cloud provider unless it's running homomorphic encryption, which is still too slow and limited to do much that is useful. I would trust them…

I feel the same and Snowden kinda said as much regarding phones. To assume each phone is compromised by state level actors.

I mean, there's a reason that the government was involved with setting up the first cell networks. No assumptions need to be involved. They ARE all compromised.
Post reply on HN