Earlier quoted context omitted.
AWS support is pretty fucking terrible generally. We’re a very high rolling enterprise customer and it’s pretty obvious that some of their shit is being managed by two guys in a shed somewhere who don’t talk to each other.
AWS Client VPN and Ubuntu 22.04... Need I say more?
Snowden leak: Cavium networking hardware may contain NSA backdoor
341–350 of 628 posts
Re: Snowden leak: Cavium networking hardware may contain NSA backdoor
#342Earlier quoted context omitted.
Addendum: if your threat model includes any nation state that has significant ties to the nation state that hosts your physical or transit infrastructure, you're hosed.
How might this apply or what are the implications of Signal given its US jurisdiction?
Re: Snowden leak: Cavium networking hardware may contain NSA backdoor
#343Earlier quoted context omitted.
> If your threat model includes... At my Fortune 250, our threat model apparently includes -- rather conveniently and coincidentally -- everything! Well, everything they make an off-the-shelf product for, anyway. It makes new purchasing decisions easy: "Does your product make any thing, in any way, more secure?" "Uh... Yes?" "You son of a bitch. We're in. Roll it out everywhere. Now."
There's no thought given to if the cost to secure the thing outweighs the risk of exposure?
Re: Snowden leak: Cavium networking hardware may contain NSA backdoor
#344Earlier quoted context omitted.
I mean, there's a reason that the government was involved with setting up the first cell networks. No assumptions need to be involved. They ARE all compromised.
Lawful intercept has always existed in phone networks. Just that one cannot use that in non-allied nations.
Re: Snowden leak: Cavium networking hardware may contain NSA backdoor
#345Earlier quoted context omitted.
It's clear that they feel that way also. The engineer Andreas Spiess recently appeared in a briefing on dangerous, anarchy-enabling technologies simply for making a youtube video on an encrypted messaging protocol over lora mesh networking. They're carefully watching and cataloging any communications technology they can't compromise.
TBF that same tech would probably be great for them or militaries to have.
Re: Snowden leak: Cavium networking hardware may contain NSA backdoor
#346Earlier quoted context omitted.
Being stranded in Moscow because the State Department cancels your passport while you're en route to Ecuador = "defection"? Cute.
I doubt Russia cared much about a cancelled US passport. If they felt he was not worth something to them they would have made sure he was out of Russia. Personally I don't think it was intentional on his part to get stuck in Russia, just a bad error. But he is certainly living there by their "good will" now, and it shows in his public behaviour.
Not trashing your host is probably wise, but given his experience with the US government, he probably no longer subscribes to the naive worldview that Putin (or Xi) are uniquely bad, just bad in their own ways and responding to the world with their nation's interests (and their legacies) in mind.
Re: Snowden leak: Cavium networking hardware may contain NSA backdoor
#347Earlier quoted context omitted.
It's clear that they feel that way also. The engineer Andreas Spiess recently appeared in a briefing on dangerous, anarchy-enabling technologies simply for making a youtube video on an encrypted messaging protocol over lora mesh networking. They're carefully watching and cataloging any communications technology they can't compromise.
It's also hard to distinguish between legitimate security threats and scare tactics designed to make us think we're in danger. Remember the Bloomberg Supermicro "bombshell"[0]? I still don't know if that was ever confirmed true or false, but to my knowledge Bloomberg never retracted it. [0] https://www.theregister.com/2021/02/12/supermicro_bloomberg_...
Re: Snowden leak: Cavium networking hardware may contain NSA backdoor
#348You can see discussion on this going on as far back as 2015, explicitly in regards to what "SIGINT enabled" means and Cavium: https://www.metzdowd.com/pipermail/cryptography/2015-Decembe...
Am I missing something here? People are talking as if there is some new backdoor that's somehow avoided detection. Did everyone just miss this discussion in 2015?
Discussion of the "Sigint Enabling Project" goes as far back as 2013 on HN itself.
Re: Snowden leak: Cavium networking hardware may contain NSA backdoor
#349The tweet seems to imply that the entire Ubiquiti Networks line of network hardware could be compromised. That's a shame; I was thinking of installing some in my house. I'm sure that Ubiquiti's customers will not be happy if they find out that the US Govt can access their private data.
if i were sniffing for outbound WAN traffic as root on the unix-like that the USG run, would i see the exfiltration traffic? or is this [supposedly/apparently] happening at a lower layer that an OS can't see i.e. some kind of BMC or BIOS layer?
wouldn't such traffic also have to navigate the varieties/restrictions of DOCSIS etc? or are they also compromised?
is the worst-case scenario here some kind of giant C2 network with waves hands tons of compromised lower-than-OS mini pieces of firmware exfiltrating data over waves hands compromised network providers hardware into the giant NSA AWS cloud?
Re: Snowden leak: Cavium networking hardware may contain NSA backdoor
#350Earlier quoted context omitted.
Is there anyone here who actually thought cloud provider HSMs were secure against the provider itself or whatever nation state(s) have jurisdiction over it? It would never occur to me to even suspect that. I assume that anything I do in the cloud is absolutely transparent to the cloud provider unless it's running homomorphic encryption, which is still too slow and limited to do much that is useful. I would trust them…
I believe this is why the government of Singapore appears to fund a lot of work on homomorphic encryption. Even when you are a nation state, you still have to worry about other nation states.