Earlier quoted context omitted.
It's quite a bit more subtle than that. News organization have their sources that are in the intelligence community. They use each other. Sometimes the journalist wants to use their sources for information. Other times their sources feed them disinformation disguised as information. Other times they want a back channel to leak some real information but can't be seem as coming from a government source. Being a good jo…
I have no sources at hand, but I understood the FBI/CIA is embedded within every major news org in the US.
Snowden leak: Cavium networking hardware may contain NSA backdoor
371–380 of 628 posts
Re: Snowden leak: Cavium networking hardware may contain NSA backdoor
#372When I buy something electronic, my approach is "everything that is closed and goes online will be used to spy on people". It may seem a stretch, but governments can't exercise power over something they cannot control, and truly private communications would take away some of that control. To me there are no conspiracy theories or other strange reasons for being able to decrypt any seemingly private information except…
If that is the case they are doing a pretty s** job spying on people, considering the amount of harm being done to children (and people in general).
Re: Snowden leak: Cavium networking hardware may contain NSA backdoor
#373Earlier quoted context omitted.
I always giggle a little when really smart people forget thugs exist and do what they’re told. If that includes breaking the knees of M people to get what they’re after, then M pairs of knees are gonna get destroyed. This isn’t hard to understand, but it’s easy to forget our civilization hangs by a thread more often than any of us care to admit.
I don't remember the provenance of the quip, but somewhere at a def con or a hope, I heard, "The point of cryptography is to force the government to torture you."
can't torture us all!
Re: Snowden leak: Cavium networking hardware may contain NSA backdoor
#374Earlier quoted context omitted.
Literally hosed. There's a funny jargon term "rubber hose cryptography" that's used to refer to the cryptanalysis method where you beat someone with a rubber hose until they give you the key. It's 100% effective against all forms of cryptography including even post-quantum algorithms.
This would not work well, because you can’t do it in a secret manner. Overuse of the rubber hose cryptography will become known, and there will be public backlash.
Re: Snowden leak: Cavium networking hardware may contain NSA backdoor
#375Earlier quoted context omitted.
>Law firms aren't terribly entrepreneurial. Personal injury guys are the most entrepreneurial people I know...
And they make money by going after low-hanging fruit. Ever wonder why they advertise 90%+ success rates and work on contingency? Because if your case isn't easy, you aren't their customer.
Re: Snowden leak: Cavium networking hardware may contain NSA backdoor
#376More interestingly, Cavium (now Marvell) also designed and manufactured the HSMs which are used by the top cloud providers (such as AWS, GCP, possibly Azure too), to hold the most critical private keys: https://www.prnewswire.com/news-releases/caviums-liquidsecur...
Ayup. We use AWS CloudHSM to hold our private signing keys for deploying field upgrades to our hardware. And when we break the CI scripts I see Cavium in the AWS logs. Now I gotta take this to our security team and figure out what to do.
I mean, you are already in US-based cloud, so if NSA is interested, they will just request information directly, no backdoors needed.
(This is a good test for your security team, btw: if they say anything other that "we do nothing", you know its all security theater)
Re: Snowden leak: Cavium networking hardware may contain NSA backdoor
#377Earlier quoted context omitted.
I have no sources at hand, but I understood the FBI/CIA is embedded within every major news org in the US.
The twitter files showed government agencies were coercing Twitter into suppressing information. I would find it hard to believe they don't also coerce at newspapers, particularly with the cozy relationship they already have with "anonymous sources" from said agencies.
They very much did not. Twitter's own lawyers when pressed in court (the place where there are consequences for lying) admitted that nothing in the "Twitter Files" cited by Donald Trump actually show that the social media platform was a tool of government censorship.
https://storage.courtlistener.com/recap/gov.uscourts.cand.38...
Re: Snowden leak: Cavium networking hardware may contain NSA backdoor
#378The tweet seems to imply that the entire Ubiquiti Networks line of network hardware could be compromised. That's a shame; I was thinking of installing some in my house. I'm sure that Ubiquiti's customers will not be happy if they find out that the US Govt can access their private data.
Ubiquiti is all cloud based. If the government wants in to your auto-updating ubnt hardware, it's just a simple court order away. They don't need a backdoor.
Re: Snowden leak: Cavium networking hardware may contain NSA backdoor
#379Earlier quoted context omitted.
…which is really weird. At least Google and Microsoft are quite outspoken about their in-house secure element technology. If nothing else, at Google/Amazon scale, I’d be concerned about a third-party HSM losing data.
It's not surprising because who wants to make their own FIPS 140-2 level 3 compliant key store device? Also, the Cavium one was the fastest one on the market the last time I looked at this. Thales, Safenet and IBM also had them..
And tech support is horrible, incompetent.
Re: Snowden leak: Cavium networking hardware may contain NSA backdoor
#380Earlier quoted context omitted.
We've had other issues with our CloudHSM instance, especially with the PKCS1.5 deprecation on January 1. And their support has been pretty dismal. Not expecting much from them at this point.
AWS support is pretty fucking terrible generally. We’re a very high rolling enterprise customer and it’s pretty obvious that some of their shit is being managed by two guys in a shed somewhere who don’t talk to each other.
I was a Linux Sysadmin for a decade. They initially hired me to work on the "BigData" support team
Then after hiring threw me into CI/CD instead. I told them I don't know python or ruby and would be a terrible fit
I asked if I can join the Linux team. EC2 is bread and butter, that's easy stuff
"Oh we're actually shutting that team down soon. I'll move you into containers instead"
Spoiler: they didn't "shut down" the Linux group