Live data from Hacker News

Snowden leak: Cavium networking hardware may contain NSA backdoor

twitter.com

411–420 of 628 posts

Re: Snowden leak: Cavium networking hardware may contain NSA backdoor

#411
post #52

More interestingly, Cavium (now Marvell) also designed and manufactured the HSMs which are used by the top cloud providers (such as AWS, GCP, possibly Azure too), to hold the most critical private keys: https://www.prnewswire.com/news-releases/caviums-liquidsecur...

Is there anyone here who actually thought cloud provider HSMs were secure against the provider itself or whatever nation state(s) have jurisdiction over it? It would never occur to me to even suspect that. I assume that anything I do in the cloud is absolutely transparent to the cloud provider unless it's running homomorphic encryption, which is still too slow and limited to do much that is useful. I would trust them…

It's interesting to consider the people who, with the very same set of facts, come to completely opposite conclusions about security.

For instance, Amazon has a staff of thousands or tens of thousands. To me, that means they can't possibly have a good grasp on internal security, that there's no way to know if and when data has been accessed improperly, et cetera. To others, the fact that they're a mega-huge company means they have security people, security processes and procedures, and they are therefore even more secure than smaller companies.

For one of the two groups, the generalized uncertainty of the small company is greater than the generalized uncertainty of the large. For the other, the size of the large makes certain things inevitable, where the security of smaller companies obviously depends on which companies we're talking about and the people involved. More often than not, people want to generalize about small companies but wouldn't apply the same criteria to larger companies like Amazon.

There's a huge emotional component in this, which I think salespeople excel at exploiting.

It fascinates me, even though it's a never-ending source of frustration.

Re: Snowden leak: Cavium networking hardware may contain NSA backdoor

#412

Earlier quoted context omitted.

> did you think blowing up schools full of girls is something people genuinely believe helps their people It absolutely is something that they think helps their people, yes.

No, it's something that a bunch of old guys with issues told them helps their people. Beliefs stop when they are no longer about yourself but about how other people should live. Especially when those other people loudly protest that this is how you think they should be living. Killing them is just murder, not the spreading of ideas. But hey, those human rights are just for decoration anyway.

> it's something that a bunch of old guys with issues told them helps their people

I don’t understand why you said “no” before this; I believe this agreed with what I’m saying.

Re: Snowden leak: Cavium networking hardware may contain NSA backdoor

#413
post #45

Earlier quoted context omitted.

I think at this point it's pretty safe to assume that all of the well-known network hardware is compromised.

I wonder if MikroTik would be compromised- they’re Latvian and don’t necessarily have to bow to the NSA.

> they’re Latvian and don’t necessarily have to bow to the NSA. reply

The majority (I'd say all) of the Eastern-European countries that are also NATO members do in fact bow to the US, and thus to the NSA/FBI/the Secret Service.

Re: Snowden leak: Cavium networking hardware may contain NSA backdoor

#414

Earlier quoted context omitted.

“100% open and auditable from the operating system to the cpu” is the main goal of the Betrusted project: https://betrusted.io/

>“100% open and auditable from the operating system to the cpu” is the main goal of the Betrusted project: https://betrusted.io/ Hopefully there's a 4G version coming. This seems too good to be true.

It's possible to modify it and add a 4G modem, but that would probably be third-party.

The creators of the project suggest using your phone's hotspot if you need connectivity when not connected to Wi-fi (something I heard in interviews they gave).

Re: Snowden leak: Cavium networking hardware may contain NSA backdoor

#415
post #45

Earlier quoted context omitted.

I wonder if MikroTik would be compromised- they’re Latvian and don’t necessarily have to bow to the NSA.

Why would the NSA need to strong arm MikroTik to implement a backdoor when they can pay ~10k for an 0-day to do the exact same thing?

Because zero day vulnerabilities are usually patched when discovered by the vendor. They're completely different than an intentional backdoor.

Re: Snowden leak: Cavium networking hardware may contain NSA backdoor

#416
post #40

Earlier quoted context omitted.

Where is the proof?

Chinese law requires Huawei to cooperate with their intelligence agencies.

That doesn't prove anything. You're just saying that Huawei could theoretically be compromised, but the above commenter asked for evidence.

Re: Snowden leak: Cavium networking hardware may contain NSA backdoor

#417
post #368

Earlier quoted context omitted.

It's not surprising because who wants to make their own FIPS 140-2 level 3 compliant key store device? Also, the Cavium one was the fastest one on the market the last time I looked at this. Thales, Safenet and IBM also had them..

Google? Titan appears to meet FIPS 140-2 level 1. I find the levels bizarre. Chromebooks are highly exposed to physical attack. Keys in the cloud are not nearly as exposed. Yet people seem okay with level 1 for chromebooks but apparently want level 3 in the cloud? I’d rather see a level 1 or level 2 auditable cloud solution, with at least source available.

Level 1 is pretty easy to meet IIRC. It's 2-4 that are hard, with pretty much no Level 4 certified ones on market I believe?

Re: Snowden leak: Cavium networking hardware may contain NSA backdoor

#418
post #331

Earlier quoted context omitted.

> If you're not under the threat cone of nation state surveillance The average reader may be surprised by how far this cone can extend in some circumstances. It has been established that the NSA conducts industrial espionage [0], under the cover of national security [1]. To what degree the term "national security" narrows down the scope of any surveillance measures is likely unfamiliar to the laymen, but an NSA repre…

> How is providing policy makers with insights from foreign politics and possible industrial espionage not giving an advantage to domestic companies, if those policy makers act appropriately? Let's imagine OpenAI was a Russian company operating mostly in secret. This RU OpenAI secretly discover and use GPT-4-like technology, and show promise that they are not done innovating. While these LLMs are often overhyped, the…

So we're evaluating the US policy on international espionage on constructed examples now?

> Let's imagine OpenAI was a Russian company

Nevermind that they're not and that Russia can't currently develop these models, due to lack of silicon. All targets I mentioned, with the exception of the brazillian oil company we're in european states, at the time (and still!) closely allied with the US.

> The distinction being made is that the NSA may steal data related to this, but they aren't just giving it to Google to make Bard better.

How would you even know at this point? Who controls the NSA? There haven't been any leaks since the Snowden revelations and there likely won't ever be any again, since Snowden could only make his move due to some misconfigured/outdated network quota control software.

Hell you can't even FOIA information about these policies, and agencies will go so far to withhold evidence in court when it concerns espionage! And soon as a court case involves this information, the court recedes from the public and is held in secret.

My hostility against US policy is by no means anywhere above the european average, but when it comes to public statements about surveillance, I have no reason to trust the US Government. The Bush administration has proven that it is possible to flout the US constitution on a massive scale with just 10-12 people. At this point I can't blame people putting forward some crazy conspiracy theories about the deep state or qanon, because the US gov has given no indication to be believably concerned about compliance with their own laws.

Re: Snowden leak: Cavium networking hardware may contain NSA backdoor

#419

Earlier quoted context omitted.

> If your threat model includes... At my Fortune 250, our threat model apparently includes -- rather conveniently and coincidentally -- everything! Well, everything they make an off-the-shelf product for, anyway. It makes new purchasing decisions easy: "Does your product make any thing, in any way, more secure?" "Uh... Yes?" "You son of a bitch. We're in. Roll it out everywhere. Now."

This reminds me of our own security team, who as far as I can tell do nothing but run POC's of new security tools. And then maybe once a year actually buy one, generating a ton of work (for others) to replace the very similar tool they bought last year. Seems like a good gig.

And the sad/funny thing is that said tool would probably do diddly squat if one employee falls for a social engineering/phishing attack.

Re: Snowden leak: Cavium networking hardware may contain NSA backdoor

#420
post #302

Earlier quoted context omitted.

> If your threat model includes... At my Fortune 250, our threat model apparently includes -- rather conveniently and coincidentally -- everything! Well, everything they make an off-the-shelf product for, anyway. It makes new purchasing decisions easy: "Does your product make any thing, in any way, more secure?" "Uh... Yes?" "You son of a bitch. We're in. Roll it out everywhere. Now."

And then when there is a security issue you ask them share the log files from all their spyware and suddenly half the stuff needed is not there because we did not get that module.

Or ‘oh, that feature hasn’t been rolled out yet, expect it in 6 quarters.’.
Post reply on HN