Live data from Hacker News

Snowden leak: Cavium networking hardware may contain NSA backdoor

twitter.com

281–290 of 628 posts

Re: Snowden leak: Cavium networking hardware may contain NSA backdoor

#281
post #168

Earlier quoted context omitted.

I feel the same and Snowden kinda said as much regarding phones. To assume each phone is compromised by state level actors.

I mean, there's a reason that the government was involved with setting up the first cell networks. No assumptions need to be involved. They ARE all compromised.

Lawful intercept has always existed in phone networks. Just that one cannot use that in non-allied nations.

Re: Snowden leak: Cavium networking hardware may contain NSA backdoor

#282
post #52

Earlier quoted context omitted.

Is there anyone here who actually thought cloud provider HSMs were secure against the provider itself or whatever nation state(s) have jurisdiction over it? It would never occur to me to even suspect that. I assume that anything I do in the cloud is absolutely transparent to the cloud provider unless it's running homomorphic encryption, which is still too slow and limited to do much that is useful. I would trust them…

> If your threat model includes... At my Fortune 250, our threat model apparently includes -- rather conveniently and coincidentally -- everything! Well, everything they make an off-the-shelf product for, anyway. It makes new purchasing decisions easy: "Does your product make any thing, in any way, more secure?" "Uh... Yes?" "You son of a bitch. We're in. Roll it out everywhere. Now."

Ahh, I've been there. I'm sure no concern is given for usability of the result.

Welding your vault shut may make it harder for thieves to break in, but if your business model requires making deposits and withdrawals, it's somewhat less helpful.

Re: Snowden leak: Cavium networking hardware may contain NSA backdoor

#283
Not even surprised, how would it be a surprise? Anyone in security field knows that hardware backdoors or even server OS memory injected backdoors are a thing and been for as long as electronics existed, but some neo-security folks get upset when you say most of the “secure” software they use isn’t really secure, chats like signal, emails like protonmail, or even VPNs, assume it’s compromised, but will it be worth it to expose that cover for what you did?

Re: Snowden leak: Cavium networking hardware may contain NSA backdoor

#284

How the NSA successfully manage to prevent the Washington Post and friends from discovering and reporting on this malicious backdoor? They've been sitting on these documents for a decade. Are the journalists just that *uncurious* about the deep contents of the documents they hold exclusive access to? Was this some kind of organizational failing?

WP is a very close ally to the government agencies in general. That's where it gets those juicy "anonymous government sources claim ..." news. If WP all of sudden wanted to prevent democracy from dying "in darkness" as their motto says, it would mean to start digging a lot harder going against the government as a whole. Don't think they are prepared for it.

Re: Snowden leak: Cavium networking hardware may contain NSA backdoor

#285

More interestingly, Cavium (now Marvell) also designed and manufactured the HSMs which are used by the top cloud providers (such as AWS, GCP, possibly Azure too), to hold the most critical private keys: https://www.prnewswire.com/news-releases/caviums-liquidsecur...

…which is really weird. At least Google and Microsoft are quite outspoken about their in-house secure element technology.

If nothing else, at Google/Amazon scale, I’d be concerned about a third-party HSM losing data.

Re: Snowden leak: Cavium networking hardware may contain NSA backdoor

#286

Earlier quoted context omitted.

“100% open and auditable from the operating system to the cpu” is the main goal of the Betrusted project: https://betrusted.io/

>“100% open and auditable from the operating system to the cpu” is the main goal of the Betrusted project: https://betrusted.io/ Hopefully there's a 4G version coming. This seems too good to be true.

The 4G modem is exceedingly unlikely to be audittable. Something like srsUE is not welcome on many telcos networks and requires some decently beefy hardware to run.

Re: Snowden leak: Cavium networking hardware may contain NSA backdoor

#287

Earlier quoted context omitted.

I'm not saying you are wrong but I can make a website which claims some cloud provider uses my hardware too. Their website is irrelevant. Do we have a Google (or AWS/...) page regarding this?

> Note: Currently, all Cloud HSM devices are manufactured by Marvell (formerly Cavium). "Cavium" and "HSM manufacturer" are currently interchangeable in this topic. https://cloud.google.com/kms/docs/attest-key

Thanks.

Also, not great, hope the hyperscalers can diversify this.

Re: Snowden leak: Cavium networking hardware may contain NSA backdoor

#288
post #205
post #185

Earlier quoted context omitted.

I generally hold a similar opinion. However I have two data points that suggests back-doors are not available by default (for my government at least), but that they are aggressively bugging (or auditing, lol) devices: * When I ordered the first generation Raspberry Pi, they were stuck in the toll a long time, and when they arrived all the warranty seals were broken. Consequently I never really used them. * When I ord…

I just assume I'm not interested enough to be spied upon by randoms > When I ordered the first generation Raspberry Pi, they were stuck in the toll a long time, and when they arrived all the warranty seals were broken. Consequently I never really used them. If state have means to bug raspberry pi it has means to re-seal the box...

> I just assume I'm not interested enough to be spied upon by randoms

I believe the fewest are. But constant surveillance is an advantage if you need to monitor general opinions or if they find you interesting at a later point and want to check your history.

So if you talk about burning wood in your stove a lot and it later becomes illegal you might have a hard time denying you have a stove if they ask you to pay extra carbon emission taxes.

Or if you talk about chest pain a lot and later want to get a new health insurance you might find that your options are mysteriously more expensive than others.

Re: Snowden leak: Cavium networking hardware may contain NSA backdoor

#290
post #225

Earlier quoted context omitted.

or you know, just don't connect your computer online.

And ensure it's not by any windows, the case HD LED doesn't blink nor does the FAN make any noise.

Both these computers were fan-less, like nearly all hobby computers at the time (clockspeeds were single digit Mhz). The Amiga only had a floppy disk drive.
Post reply on HN