Live data from Hacker News

Snowden leak: Cavium networking hardware may contain NSA backdoor

twitter.com

391–400 of 628 posts

Re: Snowden leak: Cavium networking hardware may contain NSA backdoor

#391

How the NSA successfully manage to prevent the Washington Post and friends from discovering and reporting on this malicious backdoor? They've been sitting on these documents for a decade. Are the journalists just that *uncurious* about the deep contents of the documents they hold exclusive access to? Was this some kind of organizational failing?

I don't think the journos were lazy, and I don't think there was an organisational failing. The Guardian, in particular, evidently fell out with Snowden and his collaborators; they turned on him. I assume that was coordinated with Washpo and Spiegel. That is: I think there was a decision made, to stop publishing information from the Snowden trove. I don't know what the reason for the betrayal was. I'm pretty sure Ala…

> I don't get why whistleblowers rely on newspaper publishers to unpack their leaks for the public

They have an interest in drama and a platform to publish on.

Re: Snowden leak: Cavium networking hardware may contain NSA backdoor

#392

Earlier quoted context omitted.

Sure. See you in the gulag, comerade

Comrade is of Latin origin. In Russian, tovarisch is the correct term. At least get it right if you're trying to be edgy.

Sounds like I hit a nerve?

Re: Snowden leak: Cavium networking hardware may contain NSA backdoor

#393
post #376

Earlier quoted context omitted.

Ayup. We use AWS CloudHSM to hold our private signing keys for deploying field upgrades to our hardware. And when we break the CI scripts I see Cavium in the AWS logs. Now I gotta take this to our security team and figure out what to do.

Nothing? I mean, you are already in US-based cloud, so if NSA is interested, they will just request information directly, no backdoors needed. (This is a good test for your security team, btw: if they say anything other that "we do nothing", you know its all security theater)

Very good point. That was the consensus from our team, so I think we're okay.

Ironically, the data we're securing is because of US government requirements. So if the government wants to spy on itself, who are we to say?

Re: Snowden leak: Cavium networking hardware may contain NSA backdoor

#394
post #45

Earlier quoted context omitted.

I think at this point it's pretty safe to assume that all of the well-known network hardware is compromised.

I wonder if MikroTik would be compromised- they’re Latvian and don’t necessarily have to bow to the NSA.

[deleted]

Re: Snowden leak: Cavium networking hardware may contain NSA backdoor

#395

Earlier quoted context omitted.

The terrorists that blow themselves up and that blow other people up are usually misguided brainwashed angry young men. It's nothing to do with ideology, everything to do with power. Or did you think blowing up schools full of girls is something people genuinely believe helps their people, to give just one example? Ordinary people just want to be left alone. Old guys wishing for more power will use anything to get it…

> did you think blowing up schools full of girls is something people genuinely believe helps their people It absolutely is something that they think helps their people, yes.

No, it's something that a bunch of old guys with issues told them helps their people.

Beliefs stop when they are no longer about yourself but about how other people should live. Especially when those other people loudly protest that this is how you think they should be living. Killing them is just murder, not the spreading of ideas.

But hey, those human rights are just for decoration anyway.

Re: Snowden leak: Cavium networking hardware may contain NSA backdoor

#396
Maybe there's something sinister here, or maybe Cavium and other similar network chips can be used for sigint, as well as many other things. Basically these are chips designed to look at every packet and can be programmed to take action on them. One could program a chip like this to find all the packages from user X and send an extra copy over to user Y (NSA). It's possible all this tweet means is that these NP chips are powerful and flexible enough to perform sigint. I wonder if this is like saying Intel CPUs can be used to evil things. Or C. Of course it's possible there is a back door, but that seems like the less likely scenario.

Re: Snowden leak: Cavium networking hardware may contain NSA backdoor

#397

Earlier quoted context omitted.

I always just tell people to lookup “Lavabit” to learn everything you need to know.

To save others a goog: https://en.wikipedia.org/wiki/Lavabit > Lavabit is an open-source encrypted webmail service, founded in 2004. The service suspended its operations on August 8, 2013 after the U.S. Federal Government ordered it to turn over its Secure Sockets Layer (SSL) private keys, in order to allow the government to spy on Edward Snowden's email

> He also wrote that in addition to being denied a hearing about the warrant to obtain Lavabit's user information, he was held in contempt of court. The appellate court denied his appeal due to no objection, however, he wrote that because there had been no hearing, no objection could have been raised. His contempt of court charge was also upheld on the ground that it was not disputed; similarly, he was unable to dispute the charge because there had been no hearing to do it in.

Land of the free...

Re: Snowden leak: Cavium networking hardware may contain NSA backdoor

#398
post #52

Earlier quoted context omitted.

Is there anyone here who actually thought cloud provider HSMs were secure against the provider itself or whatever nation state(s) have jurisdiction over it? It would never occur to me to even suspect that. I assume that anything I do in the cloud is absolutely transparent to the cloud provider unless it's running homomorphic encryption, which is still too slow and limited to do much that is useful. I would trust them…

See the Cryptographic Control Over Data Access [0] section here for one answer to this problem. [0] https://cloud.google.com/blog/products/identity-security/new...

That's nice, but the only reasons that public clients would use a well known bad actor from a rogue state is laziness / incompetence.

Re: Snowden leak: Cavium networking hardware may contain NSA backdoor

#399
post #143

Earlier quoted context omitted.

AWS support is pretty fucking terrible generally. We’re a very high rolling enterprise customer and it’s pretty obvious that some of their shit is being managed by two guys in a shed somewhere who don’t talk to each other.

Have you had the pleasure of working with Azure? I'll take AWS any day over that dumpster fire.

As someone that is deciding between AWS, Google and Azure - could give an outline of some of the Azure painpoints? Are there any blogs or other articles that outlines what your concerns would be?

I'm pretty aware of how painful it can be to configure AWS well, IAM roles, the overly large eco-system that we won't need and unmitigated complexity to configure it all. It's not comforting to think Azure is worse yet.

Re: Snowden leak: Cavium networking hardware may contain NSA backdoor

#400
post #352

Earlier quoted context omitted.

Ubiquiti is all cloud based. If the government wants in to your auto-updating ubnt hardware, it's just a simple court order away. They don't need a backdoor.

It may be auto-updating by default, but that can be trivially disabled. Likewise, their cloud connectivity/management is optional. I'm running without issue multiple air-gapped Ubnt networks using their self-hosted controller software.

Yeh but it is still closed source, no? I guess if it is air gapped that could be fine, but we are talking mid level network gear here, so for 99% of its use, it isn't air gapped. It is enabling broader connectivity. So you would have to trust the closed source software at some point.
Post reply on HN