Live data from Hacker News

Snowden leak: Cavium networking hardware may contain NSA backdoor

twitter.com

361–370 of 628 posts

Re: Snowden leak: Cavium networking hardware may contain NSA backdoor

#361

Earlier quoted context omitted.

[flagged]

I'd usually agree, except when it comes to saying anything critical of China on the Internet, my statement is very true. The wumao is a real thing, and they're pervasive within online tech.

Well your comment isn't greyed out or flagged, so they must be on vacation today :)

Re: Snowden leak: Cavium networking hardware may contain NSA backdoor

#363

More interestingly, Cavium (now Marvell) also designed and manufactured the HSMs which are used by the top cloud providers (such as AWS, GCP, possibly Azure too), to hold the most critical private keys: https://www.prnewswire.com/news-releases/caviums-liquidsecur...

Ayup. We use AWS CloudHSM to hold our private signing keys for deploying field upgrades to our hardware. And when we break the CI scripts I see Cavium in the AWS logs. Now I gotta take this to our security team and figure out what to do.

Nobody cares. If caring gets in the way of easy money. Spoiler...it does.

Re: Snowden leak: Cavium networking hardware may contain NSA backdoor

#364

Earlier quoted context omitted.

Terrorists are generally highly altruistic, not psychopaths. It’s a lot easier to blow yourself up(or to spread ideology which encourages it)for a cause that you believe is helping people, in particular _your_ people.

The terrorists that blow themselves up and that blow other people up are usually misguided brainwashed angry young men. It's nothing to do with ideology, everything to do with power. Or did you think blowing up schools full of girls is something people genuinely believe helps their people, to give just one example? Ordinary people just want to be left alone. Old guys wishing for more power will use anything to get it…

> did you think blowing up schools full of girls is something people genuinely believe helps their people

It absolutely is something that they think helps their people, yes.

Re: Snowden leak: Cavium networking hardware may contain NSA backdoor

#365

If your threat model is Nation states, then you probably have a lot more to worry about than this chip, including compromising employees which is way easier, cheaper, and more effective.

The risk impact isn’t just nation states though. Intentionally weakened hardware makes you more vulnerable across the entire threat actor spectrum. Any of them could stumble across it whether through skill or luck.

Re: Snowden leak: Cavium networking hardware may contain NSA backdoor

#366

Earlier quoted context omitted.

Ubiquiti has many other problems besides this. The worst is their vendor lockin, where even basic network operations are not possible if you happen to have any non-ubiquiti hardware in your network. You should stay away.

Can you provide an example of this issue? This has not been my experience.

People are misinterpreting me, thinking I mean that it's not even possible to intermingle equipment. That is not the case.

The specific issue I ran into was that I had a non-ubuiqiti router and AP on my network, and there was absolutely no way to set firewall rules on the Ubiquiti gateway for any clients connected through the non-ubiquiti equipment. This should obviously not be a problem. The gateway provided those clients IP addresses through DHCP and they are in its ARP table, so it should be supported.

Re: Snowden leak: Cavium networking hardware may contain NSA backdoor

#367

Another tragic blow to the environment and economy. We treat these stories as if they were simple matters of politics and tech. But the blast radius is huge. When this happened to Cisco, and their value dropped to about 7% of the market they created, I passed massive dumpsters of Cisco gear in the car park, prematurely torn out of racks and consigned to crushing as e-waste. Has anyone done a serious cost analysis of…

Where can I find dumpsters of Cisco gears? I guess they are good targets to hack on.

Re: Snowden leak: Cavium networking hardware may contain NSA backdoor

#368
post #285

Earlier quoted context omitted.

…which is really weird. At least Google and Microsoft are quite outspoken about their in-house secure element technology. If nothing else, at Google/Amazon scale, I’d be concerned about a third-party HSM losing data.

It's not surprising because who wants to make their own FIPS 140-2 level 3 compliant key store device? Also, the Cavium one was the fastest one on the market the last time I looked at this. Thales, Safenet and IBM also had them..

Google? Titan appears to meet FIPS 140-2 level 1.

I find the levels bizarre. Chromebooks are highly exposed to physical attack. Keys in the cloud are not nearly as exposed. Yet people seem okay with level 1 for chromebooks but apparently want level 3 in the cloud?

I’d rather see a level 1 or level 2 auditable cloud solution, with at least source available.

Re: Snowden leak: Cavium networking hardware may contain NSA backdoor

#369

Earlier quoted context omitted.

I don't remember the provenance of the quip, but somewhere at a def con or a hope, I heard, "The point of cryptography is to force the government to torture you."

They're perfectly ok with that, and depending on where you live this may happen in more or less overt ways. If the government wants your information, they will get your information. Your very best outcome is to simply rot in detention until you cough up your keys.

Now that I think about it, I'm pretty sure it was a session about root zone security, and Adam Langley was in the room. I was thinking, damn, kinda sucks to be the guy that holds Google's private keys. They want someone's information, so they let you rot...

Re: Snowden leak: Cavium networking hardware may contain NSA backdoor

#370
post #52

Earlier quoted context omitted.

Is there anyone here who actually thought cloud provider HSMs were secure against the provider itself or whatever nation state(s) have jurisdiction over it? It would never occur to me to even suspect that. I assume that anything I do in the cloud is absolutely transparent to the cloud provider unless it's running homomorphic encryption, which is still too slow and limited to do much that is useful. I would trust them…

> If your threat model includes... At my Fortune 250, our threat model apparently includes -- rather conveniently and coincidentally -- everything! Well, everything they make an off-the-shelf product for, anyway. It makes new purchasing decisions easy: "Does your product make any thing, in any way, more secure?" "Uh... Yes?" "You son of a bitch. We're in. Roll it out everywhere. Now."

This reminds me of our own security team, who as far as I can tell do nothing but run POC's of new security tools. And then maybe once a year actually buy one, generating a ton of work (for others) to replace the very similar tool they bought last year. Seems like a good gig.
Post reply on HN