Live data from Hacker News

Snowden leak: Cavium networking hardware may contain NSA backdoor

twitter.com

321–330 of 628 posts

Re: Snowden leak: Cavium networking hardware may contain NSA backdoor

#321
post #56

Earlier quoted context omitted.

Law firms aren't terribly entrepreneurial. Absent somebody paying them their hourly rate, I suspect not a single document would be read. Newspapers regularly take risks deploying humans to investigate issues without any assurance there will be a story at the bottom, but even the newspaper business has less appetite for that these days (as an aside, I suspect it's that margin that the financial investors have exploite…

>Law firms aren't terribly entrepreneurial. Personal injury guys are the most entrepreneurial people I know...

[deleted]

Re: Snowden leak: Cavium networking hardware may contain NSA backdoor

#323

Earlier quoted context omitted.

Snowden leaked a shit ton of documents, the vast majority of which had absolutely nothing to do with any kind of NSA wrongdoing. Journalists then had to go through and try to figure out what these documents actually meant (which they frequently misunderstood). Obviously they're still doing it to today.

>Snowden leaked a shit ton of documents, the vast majority of which had absolutely nothing to do with any kind of NSA wrongdoing Like how NSA collects a shit ton of data on citizens... the vast majority of which has absolutely nothing to do with any kind of wrongdoing. I'm only pointing this out because your comment has a negative tone towards what Snowden did.

I didn't read anything negative in there. GP might have been negative but I don't think there's enough to tell just from the post

Re: Snowden leak: Cavium networking hardware may contain NSA backdoor

#325
post #52

More interestingly, Cavium (now Marvell) also designed and manufactured the HSMs which are used by the top cloud providers (such as AWS, GCP, possibly Azure too), to hold the most critical private keys: https://www.prnewswire.com/news-releases/caviums-liquidsecur...

Is there anyone here who actually thought cloud provider HSMs were secure against the provider itself or whatever nation state(s) have jurisdiction over it? It would never occur to me to even suspect that. I assume that anything I do in the cloud is absolutely transparent to the cloud provider unless it's running homomorphic encryption, which is still too slow and limited to do much that is useful. I would trust them…

You don't need to think about this in a binary fashion. You can split your trust across multiple entities. Different clouds, different countries, or a mix of cloud and data centers you own.

Re: Snowden leak: Cavium networking hardware may contain NSA backdoor

#327
post #6

The tweet seems to imply that the entire Ubiquiti Networks line of network hardware could be compromised. That's a shame; I was thinking of installing some in my house. I'm sure that Ubiquiti's customers will not be happy if they find out that the US Govt can access their private data.

[deleted]

Re: Snowden leak: Cavium networking hardware may contain NSA backdoor

#328
post #45

Earlier quoted context omitted.

I think at this point it's pretty safe to assume that all of the well-known network hardware is compromised.

I wonder if MikroTik would be compromised- they’re Latvian and don’t necessarily have to bow to the NSA.

i've always assumed they were the least secure of all my networking hardware

Re: Snowden leak: Cavium networking hardware may contain NSA backdoor

#329

Earlier quoted context omitted.

Trying to understand what crypto is the network hardware itself performing? TLS is end to end, even if you run a VPN on the router the keys were not generated there probably

crypto doesn't matter if chip itself has backdoor that will grant root access on some "magic" packet

Crypto matters for exactly this reason. All my internet traffic passes through unsafe middle-boxes, it is TLS and DH that make sure I can pass through untrusted middlemen without them knowing what is going on.

Re: Snowden leak: Cavium networking hardware may contain NSA backdoor

#330
post #6

The tweet seems to imply that the entire Ubiquiti Networks line of network hardware could be compromised. That's a shame; I was thinking of installing some in my house. I'm sure that Ubiquiti's customers will not be happy if they find out that the US Govt can access their private data.

Some specific Ubiquiti gear uses Cavium SOCs, but certainly not all. The UDM Pro uses an Annapurna Labs SOC and my old EdgeRouter-X was Mediatek.
Post reply on HN