Earlier quoted context omitted.
[flagged]
I'd usually agree, except when it comes to saying anything critical of China on the Internet, my statement is very true. The wumao is a real thing, and they're pervasive within online tech.
Snowden leak: Cavium networking hardware may contain NSA backdoor
361–370 of 628 posts
Re: Snowden leak: Cavium networking hardware may contain NSA backdoor
#362Re: Snowden leak: Cavium networking hardware may contain NSA backdoor
#363More interestingly, Cavium (now Marvell) also designed and manufactured the HSMs which are used by the top cloud providers (such as AWS, GCP, possibly Azure too), to hold the most critical private keys: https://www.prnewswire.com/news-releases/caviums-liquidsecur...
Ayup. We use AWS CloudHSM to hold our private signing keys for deploying field upgrades to our hardware. And when we break the CI scripts I see Cavium in the AWS logs. Now I gotta take this to our security team and figure out what to do.
Re: Snowden leak: Cavium networking hardware may contain NSA backdoor
#364Earlier quoted context omitted.
Terrorists are generally highly altruistic, not psychopaths. It’s a lot easier to blow yourself up(or to spread ideology which encourages it)for a cause that you believe is helping people, in particular _your_ people.
The terrorists that blow themselves up and that blow other people up are usually misguided brainwashed angry young men. It's nothing to do with ideology, everything to do with power. Or did you think blowing up schools full of girls is something people genuinely believe helps their people, to give just one example? Ordinary people just want to be left alone. Old guys wishing for more power will use anything to get it…
It absolutely is something that they think helps their people, yes.
Re: Snowden leak: Cavium networking hardware may contain NSA backdoor
#365If your threat model is Nation states, then you probably have a lot more to worry about than this chip, including compromising employees which is way easier, cheaper, and more effective.
Re: Snowden leak: Cavium networking hardware may contain NSA backdoor
#366Earlier quoted context omitted.
Ubiquiti has many other problems besides this. The worst is their vendor lockin, where even basic network operations are not possible if you happen to have any non-ubiquiti hardware in your network. You should stay away.
Can you provide an example of this issue? This has not been my experience.
The specific issue I ran into was that I had a non-ubuiqiti router and AP on my network, and there was absolutely no way to set firewall rules on the Ubiquiti gateway for any clients connected through the non-ubiquiti equipment. This should obviously not be a problem. The gateway provided those clients IP addresses through DHCP and they are in its ARP table, so it should be supported.
Re: Snowden leak: Cavium networking hardware may contain NSA backdoor
#367Another tragic blow to the environment and economy. We treat these stories as if they were simple matters of politics and tech. But the blast radius is huge. When this happened to Cisco, and their value dropped to about 7% of the market they created, I passed massive dumpsters of Cisco gear in the car park, prematurely torn out of racks and consigned to crushing as e-waste. Has anyone done a serious cost analysis of…
Re: Snowden leak: Cavium networking hardware may contain NSA backdoor
#368Earlier quoted context omitted.
…which is really weird. At least Google and Microsoft are quite outspoken about their in-house secure element technology. If nothing else, at Google/Amazon scale, I’d be concerned about a third-party HSM losing data.
It's not surprising because who wants to make their own FIPS 140-2 level 3 compliant key store device? Also, the Cavium one was the fastest one on the market the last time I looked at this. Thales, Safenet and IBM also had them..
I find the levels bizarre. Chromebooks are highly exposed to physical attack. Keys in the cloud are not nearly as exposed. Yet people seem okay with level 1 for chromebooks but apparently want level 3 in the cloud?
I’d rather see a level 1 or level 2 auditable cloud solution, with at least source available.
Re: Snowden leak: Cavium networking hardware may contain NSA backdoor
#369Earlier quoted context omitted.
I don't remember the provenance of the quip, but somewhere at a def con or a hope, I heard, "The point of cryptography is to force the government to torture you."
They're perfectly ok with that, and depending on where you live this may happen in more or less overt ways. If the government wants your information, they will get your information. Your very best outcome is to simply rot in detention until you cough up your keys.
Re: Snowden leak: Cavium networking hardware may contain NSA backdoor
#370Earlier quoted context omitted.
Is there anyone here who actually thought cloud provider HSMs were secure against the provider itself or whatever nation state(s) have jurisdiction over it? It would never occur to me to even suspect that. I assume that anything I do in the cloud is absolutely transparent to the cloud provider unless it's running homomorphic encryption, which is still too slow and limited to do much that is useful. I would trust them…
> If your threat model includes... At my Fortune 250, our threat model apparently includes -- rather conveniently and coincidentally -- everything! Well, everything they make an off-the-shelf product for, anyway. It makes new purchasing decisions easy: "Does your product make any thing, in any way, more secure?" "Uh... Yes?" "You son of a bitch. We're in. Roll it out everywhere. Now."