Live data from Hacker News

Snowden leak: Cavium networking hardware may contain NSA backdoor

twitter.com

331–340 of 628 posts

Re: Snowden leak: Cavium networking hardware may contain NSA backdoor

#331

Earlier quoted context omitted.

If you're not under the threat cone of nation state surveillance (like trying to exfiltrate the radar-asborbing paint formula on the F35) then I wouldn't be too concerned. "That's not the point! It's about privacy!" Sure. I'll choose it ignore the fact that our civilization is somehow still functioning in a post-nuclear world.

> If you're not under the threat cone of nation state surveillance The average reader may be surprised by how far this cone can extend in some circumstances. It has been established that the NSA conducts industrial espionage [0], under the cover of national security [1]. To what degree the term "national security" narrows down the scope of any surveillance measures is likely unfamiliar to the laymen, but an NSA repre…

> How is providing policy makers with insights from foreign politics and possible industrial espionage not giving an advantage to domestic companies, if those policy makers act appropriately?

Let's imagine OpenAI was a Russian company operating mostly in secret. This RU OpenAI secretly discover and use GPT-4-like technology, and show promise that they are not done innovating. While these LLMs are often overhyped, these recent innovations no doubt present a policy issue, right? I'd say there are legitimate national security reasons to know about that technology, not just about making money or making a better product for cheap.

The distinction being made is that the NSA may steal data related to this, but they aren't just giving it to Google to make Bard better. They are getting intel and giving lawmakers the tools to fund research, write policy, or whatever else our elected representatives deem beneficial. Any side action or under the table dealings would make this distinction meaningless of course. So, for the example above, if we started funding departments to research the threat of LLMs/AI, inform the public of the issue, and inform companies that their data is being pillaged to train AI... that is all very different from just stealing a cool new widget design and getting it to market first.

I think there's no debating that this is morally gray, but I think it's a few steps off of what other nation states are doing by stealing tech and implementing it in "private" companies. It's certainly worthy of criticism, but I think it's unhelpful to bucket it with the other type.

If the LLM example isn't your thing, it also makes a lot of sense for the NSA to steal information related to weapon/defense tech, even if developed by a private company, and even if we use what we stole to implement countermeasures. I can't honestly be morally outraged about invading the privacy of someone developing tools of war against you. Fwiw, I wouldn't blame Russia or China for trying this against the US gov or defense contractors either, but it's not like I'd be happy about it. My point is that that is not so much economic espionage or corporate espionage as much as it is just plain old espionage. It saves lives and protects American hegemony - which I recognize may be counter to many people's ideal situation.

It's a nuanced thing. When you take two morally questionable things and reduce them down to both just being bad, the ones doing the worse things benefit. E.g. "all politicians lie" is a handy phrase for truly corrupt politicians because the ones who make small mistakes or half-truths are in the same bucket as them, and the outcome is apathy for the issue rather than being upset at all of it. Kinda the classic whataboutism trope - not to imply you are doing that, but just to say that's where it often leads.

Re: Snowden leak: Cavium networking hardware may contain NSA backdoor

#332

Earlier quoted context omitted.

[flagged]

[flagged]

I'd usually agree, except when it comes to saying anything critical of China on the Internet, my statement is very true. The wumao is a real thing, and they're pervasive within online tech.

Re: Snowden leak: Cavium networking hardware may contain NSA backdoor

#333
post #243

Is this only limited to “USG” products? Or safe to assume UDM also impacted? edit: FUCK “ Quad-core ARM® Cortex®-A57 at 1.7 GHz” https://store.ui.com/us/en/pro/category/all-unifi-gateway-co... People paying premium $$$ for this. UI better redesign and compensate users.

Cavium provides purpose-built chips used for the ER & USG products. The UDM line uses ARM chips, most likely built by Annapurna labs.

Re: Snowden leak: Cavium networking hardware may contain NSA backdoor

#335
post #213

Earlier quoted context omitted.

You would be surprised that for a percent this would not work. Some even like it. Some have a deathwish and want to be a martyr. Some people blow themselves up to further a cause. Also put under heavy stress memories of keys cannot be recalled at times. It's probably slightly less effective than threatening to kill family members but probably more than threat of jail time. Either way you require someone alive and wit…

We're talking about normal people, not psychopaths.

Terrorists are generally highly altruistic, not psychopaths.

It’s a lot easier to blow yourself up(or to spread ideology which encourages it)for a cause that you believe is helping people, in particular _your_ people.

Re: Snowden leak: Cavium networking hardware may contain NSA backdoor

#336
post #19

Earlier quoted context omitted.

I suspect when a trove of documents is big enough, newspaper readers lose interest before you run out of documents. I mean, even on this tech forum hardly anyone knows who Cavium are, let alone your average Washington Post reader.

Maybe the moral of the story is that future snowdens should leak to selected law firms instead of selected journalists? If there's one organization designed to comb through large documents for details and understand the impacts to potential parties, it is law organizations. Put 2-3 in time competition to make cases out of the documents and it will be a scramble race for justice.

You'd be surprised. Top journalism organizations do this kind of thing with tremendous efficiency. The Pandora Papers were impressive for exactly that reason.

Re: Snowden leak: Cavium networking hardware may contain NSA backdoor

#337

When I buy something electronic, my approach is "everything that is closed and goes online will be used to spy on people". It may seem a stretch, but governments can't exercise power over something they cannot control, and truly private communications would take away some of that control. To me there are no conspiracy theories or other strange reasons for being able to decrypt any seemingly private information except…

It's clear that they feel that way also. The engineer Andreas Spiess recently appeared in a briefing on dangerous, anarchy-enabling technologies simply for making a youtube video on an encrypted messaging protocol over lora mesh networking. They're carefully watching and cataloging any communications technology they can't compromise.

TBF that same tech would probably be great for them or militaries to have.

Re: Snowden leak: Cavium networking hardware may contain NSA backdoor

#339
post #285

More interestingly, Cavium (now Marvell) also designed and manufactured the HSMs which are used by the top cloud providers (such as AWS, GCP, possibly Azure too), to hold the most critical private keys: https://www.prnewswire.com/news-releases/caviums-liquidsecur...

…which is really weird. At least Google and Microsoft are quite outspoken about their in-house secure element technology. If nothing else, at Google/Amazon scale, I’d be concerned about a third-party HSM losing data.

It's not surprising because who wants to make their own FIPS 140-2 level 3 compliant key store device?

Also, the Cavium one was the fastest one on the market the last time I looked at this. Thales, Safenet and IBM also had them..

Re: Snowden leak: Cavium networking hardware may contain NSA backdoor

#340
post #312

Earlier quoted context omitted.

> If your threat model includes... At my Fortune 250, our threat model apparently includes -- rather conveniently and coincidentally -- everything! Well, everything they make an off-the-shelf product for, anyway. It makes new purchasing decisions easy: "Does your product make any thing, in any way, more secure?" "Uh... Yes?" "You son of a bitch. We're in. Roll it out everywhere. Now."

There's no thought given to if the cost to secure the thing outweighs the risk of exposure?

[deleted]
Post reply on HN