Live data from Hacker News

Snowden leak: Cavium networking hardware may contain NSA backdoor

twitter.com

301–310 of 628 posts

Re: Snowden leak: Cavium networking hardware may contain NSA backdoor

#301

Earlier quoted context omitted.

This is the thing that rubs me the wrong way about Snowden - had he stayed and faced the music as a true whistleblower, he would've earned my respect for sticking to principles and acting as a loyal citizen acting in the interest of the country, even in the face of persecution. He did not do that. Instead, he's living a comfortable life in the bowels of a country that is committing vicious, daily war crimes. I don't…

As a contractor he didn't qualify for whistleblower protections at the time. He would just be in solitary confinement for the rest of his life, and there's a much better chance the leak to the public would have never been completed in the first.

I see no evidence that merely being convicted of treason is enough to get you thrown in a solitary cell forever. There's a long list of plain old convicted spies[1], and they just went to regular, run of the mill prison. I would like to see the evidence that Snowden would be treated any differently.

And again, I'm not saying he would've been protected as a whistleblower, just that he had to choose one or the other: take his chances as a martyr for freedom, or escape all consequences and with them, his legacy as a respectable historical figure. He chose the latter.

[1] https://en.wikipedia.org/wiki/List_of_imprisoned_spies

Re: Snowden leak: Cavium networking hardware may contain NSA backdoor

#302
post #52

Earlier quoted context omitted.

Is there anyone here who actually thought cloud provider HSMs were secure against the provider itself or whatever nation state(s) have jurisdiction over it? It would never occur to me to even suspect that. I assume that anything I do in the cloud is absolutely transparent to the cloud provider unless it's running homomorphic encryption, which is still too slow and limited to do much that is useful. I would trust them…

> If your threat model includes... At my Fortune 250, our threat model apparently includes -- rather conveniently and coincidentally -- everything! Well, everything they make an off-the-shelf product for, anyway. It makes new purchasing decisions easy: "Does your product make any thing, in any way, more secure?" "Uh... Yes?" "You son of a bitch. We're in. Roll it out everywhere. Now."

And then when there is a security issue you ask them share the log files from all their spyware and suddenly half the stuff needed is not there because we did not get that module.

Re: Snowden leak: Cavium networking hardware may contain NSA backdoor

#303
post #300

I don’t know much about security, especially at the hardware level. However, I have a question for those of you that do. Suppose you were given a healthy budget, a team, and a few years. Would you be able to build network hardware that did not contain back doors? How healthy would the budget need to be? How skilled would the team need to be? I assume you’d have to assume most external vendors are compromised and rebu…

Impossible. Sooner or later one of the 3 letter agencies would have somebody on your team and they would introduce multiple backdoors one way or another.

Re: Snowden leak: Cavium networking hardware may contain NSA backdoor

#304

When I buy something electronic, my approach is "everything that is closed and goes online will be used to spy on people". It may seem a stretch, but governments can't exercise power over something they cannot control, and truly private communications would take away some of that control. To me there are no conspiracy theories or other strange reasons for being able to decrypt any seemingly private information except…

If that is the case they are doing a pretty s** job spying on people, considering the amount of harm being done to children (and people in general).

Re: Snowden leak: Cavium networking hardware may contain NSA backdoor

#305
post #105

Earlier quoted context omitted.

China is way less dangerous to me than the NSA

How is the NSA personally dangerous to you?

Compared to any TLAs in China, the NSA is far more likely to take action against a US citizen for a thing that citizen chose to say. It's likely there's a low amount of actual danger but it's greater than that of what China poses.

Re: Snowden leak: Cavium networking hardware may contain NSA backdoor

#306
post #105

Earlier quoted context omitted.

China is way less dangerous to me than the NSA

How is the NSA personally dangerous to you?

If you live in the US, you're under US federal jurisdiction.

Unless you're regularly traveling to China or unearthing info that can seriously harm China, they're not going to send anyone after you.

I rather be spied on by a foreign government than my own.

Re: Snowden leak: Cavium networking hardware may contain NSA backdoor

#307

Earlier quoted context omitted.

A Mann is being executed in Saudia Arabia for tweeting a negative tweet about the government to his tiny following. Not exactly someone who thinks they are a target of a nation state. [1] https://www.hrw.org/news/2023/08/29/saudi-arabia-man-sentenc...

Not sure if this a joke but SA is the exact country I would expect to utilize spyware against its citizens.

With how good of friends SA is with the US, its likely all they need to do is ask nicely for some dirt on an alleged dissident.

Re: Snowden leak: Cavium networking hardware may contain NSA backdoor

#308
post #300

I don’t know much about security, especially at the hardware level. However, I have a question for those of you that do. Suppose you were given a healthy budget, a team, and a few years. Would you be able to build network hardware that did not contain back doors? How healthy would the budget need to be? How skilled would the team need to be? I assume you’d have to assume most external vendors are compromised and rebu…

I don't think it would be that hard. There's RISC-V SBCs out there which the schematics are open for. I don't think it's correct to assume absolutely everything out there is backdoored/compromised. That would be an very difficult undertaking and word would get out. NSA target their attacks very finely.

Re: Snowden leak: Cavium networking hardware may contain NSA backdoor

#309

Earlier quoted context omitted.

If you're not under the threat cone of nation state surveillance (like trying to exfiltrate the radar-asborbing paint formula on the F35) then I wouldn't be too concerned. "That's not the point! It's about privacy!" Sure. I'll choose it ignore the fact that our civilization is somehow still functioning in a post-nuclear world.

Sure. See you in the gulag, comerade

Gulag is just Russian for prison.

The US currently has about 1.2M people in their gulags, comrade*

Re: Snowden leak: Cavium networking hardware may contain NSA backdoor

#310
post #143

Earlier quoted context omitted.

We've had other issues with our CloudHSM instance, especially with the PKCS1.5 deprecation on January 1. And their support has been pretty dismal. Not expecting much from them at this point.

AWS support is pretty fucking terrible generally. We’re a very high rolling enterprise customer and it’s pretty obvious that some of their shit is being managed by two guys in a shed somewhere who don’t talk to each other.

AWS Client VPN and Ubuntu 22.04... Need I say more?
Post reply on HN