Earlier quoted context omitted.
I feel the same and Snowden kinda said as much regarding phones. To assume each phone is compromised by state level actors.
I mean, there's a reason that the government was involved with setting up the first cell networks. No assumptions need to be involved. They ARE all compromised.
Snowden leak: Cavium networking hardware may contain NSA backdoor
281–290 of 628 posts
Re: Snowden leak: Cavium networking hardware may contain NSA backdoor
#282Earlier quoted context omitted.
Is there anyone here who actually thought cloud provider HSMs were secure against the provider itself or whatever nation state(s) have jurisdiction over it? It would never occur to me to even suspect that. I assume that anything I do in the cloud is absolutely transparent to the cloud provider unless it's running homomorphic encryption, which is still too slow and limited to do much that is useful. I would trust them…
> If your threat model includes... At my Fortune 250, our threat model apparently includes -- rather conveniently and coincidentally -- everything! Well, everything they make an off-the-shelf product for, anyway. It makes new purchasing decisions easy: "Does your product make any thing, in any way, more secure?" "Uh... Yes?" "You son of a bitch. We're in. Roll it out everywhere. Now."
Welding your vault shut may make it harder for thieves to break in, but if your business model requires making deposits and withdrawals, it's somewhat less helpful.
Re: Snowden leak: Cavium networking hardware may contain NSA backdoor
#283Re: Snowden leak: Cavium networking hardware may contain NSA backdoor
#284How the NSA successfully manage to prevent the Washington Post and friends from discovering and reporting on this malicious backdoor? They've been sitting on these documents for a decade. Are the journalists just that *uncurious* about the deep contents of the documents they hold exclusive access to? Was this some kind of organizational failing?
Re: Snowden leak: Cavium networking hardware may contain NSA backdoor
#285More interestingly, Cavium (now Marvell) also designed and manufactured the HSMs which are used by the top cloud providers (such as AWS, GCP, possibly Azure too), to hold the most critical private keys: https://www.prnewswire.com/news-releases/caviums-liquidsecur...
If nothing else, at Google/Amazon scale, I’d be concerned about a third-party HSM losing data.
Re: Snowden leak: Cavium networking hardware may contain NSA backdoor
#286Earlier quoted context omitted.
“100% open and auditable from the operating system to the cpu” is the main goal of the Betrusted project: https://betrusted.io/
>“100% open and auditable from the operating system to the cpu” is the main goal of the Betrusted project: https://betrusted.io/ Hopefully there's a 4G version coming. This seems too good to be true.
Re: Snowden leak: Cavium networking hardware may contain NSA backdoor
#287Earlier quoted context omitted.
I'm not saying you are wrong but I can make a website which claims some cloud provider uses my hardware too. Their website is irrelevant. Do we have a Google (or AWS/...) page regarding this?
> Note: Currently, all Cloud HSM devices are manufactured by Marvell (formerly Cavium). "Cavium" and "HSM manufacturer" are currently interchangeable in this topic. https://cloud.google.com/kms/docs/attest-key
Also, not great, hope the hyperscalers can diversify this.
Re: Snowden leak: Cavium networking hardware may contain NSA backdoor
#288Earlier quoted context omitted.
I generally hold a similar opinion. However I have two data points that suggests back-doors are not available by default (for my government at least), but that they are aggressively bugging (or auditing, lol) devices: * When I ordered the first generation Raspberry Pi, they were stuck in the toll a long time, and when they arrived all the warranty seals were broken. Consequently I never really used them. * When I ord…
I just assume I'm not interested enough to be spied upon by randoms > When I ordered the first generation Raspberry Pi, they were stuck in the toll a long time, and when they arrived all the warranty seals were broken. Consequently I never really used them. If state have means to bug raspberry pi it has means to re-seal the box...
I believe the fewest are. But constant surveillance is an advantage if you need to monitor general opinions or if they find you interesting at a later point and want to check your history.
So if you talk about burning wood in your stove a lot and it later becomes illegal you might have a hard time denying you have a stove if they ask you to pay extra carbon emission taxes.
Or if you talk about chest pain a lot and later want to get a new health insurance you might find that your options are mysteriously more expensive than others.
Re: Snowden leak: Cavium networking hardware may contain NSA backdoor
#289Re: Snowden leak: Cavium networking hardware may contain NSA backdoor
#290Earlier quoted context omitted.
or you know, just don't connect your computer online.
And ensure it's not by any windows, the case HD LED doesn't blink nor does the FAN make any noise.