Earlier quoted context omitted.
> If your threat model includes... At my Fortune 250, our threat model apparently includes -- rather conveniently and coincidentally -- everything! Well, everything they make an off-the-shelf product for, anyway. It makes new purchasing decisions easy: "Does your product make any thing, in any way, more secure?" "Uh... Yes?" "You son of a bitch. We're in. Roll it out everywhere. Now."
Ahh, I've been there. I'm sure no concern is given for usability of the result. Welding your vault shut may make it harder for thieves to break in, but if your business model requires making deposits and withdrawals, it's somewhat less helpful.
Snowden leak: Cavium networking hardware may contain NSA backdoor
421–430 of 628 posts
Re: Snowden leak: Cavium networking hardware may contain NSA backdoor
#422[flagged]
Huawei stuff is proven to be compromised, just not by NSA, instead by China.
This is despite the fact that Huawei has been under an extraordinary level of scrutiny for years. British intelligence was given extensive access to Huawei's hardware and code, as a condition of Huawei equipment being installed in the UK. We know from Snowden that the NSA hacked into Huawei HQ, but there's no indication that they found any evidence of backdoors. And despite running a global campaign to convince/pressure other countries not to use Huawei, the US hasn't publicly unveiled any evidence of Huawei backdoors. British officials have even admitted that the UK's decision to ban Huawei was based on pressure from the US, not evidence of wrongdoing.[0,1] This all makes me think that the US, UK et al. don't actually have proof of backdoors.
0. https://www.theguardian.com/technology/2020/jul/18/pressure-...
1. https://www.euractiv.com/section/politics/short_news/uk-bann...
Re: Snowden leak: Cavium networking hardware may contain NSA backdoor
#423Earlier quoted context omitted.
Ayup. We use AWS CloudHSM to hold our private signing keys for deploying field upgrades to our hardware. And when we break the CI scripts I see Cavium in the AWS logs. Now I gotta take this to our security team and figure out what to do.
Nothing? I mean, you are already in US-based cloud, so if NSA is interested, they will just request information directly, no backdoors needed. (This is a good test for your security team, btw: if they say anything other that "we do nothing", you know its all security theater)
Re: Snowden leak: Cavium networking hardware may contain NSA backdoor
#424Earlier quoted context omitted.
Google? Titan appears to meet FIPS 140-2 level 1. I find the levels bizarre. Chromebooks are highly exposed to physical attack. Keys in the cloud are not nearly as exposed. Yet people seem okay with level 1 for chromebooks but apparently want level 3 in the cloud? I’d rather see a level 1 or level 2 auditable cloud solution, with at least source available.
Level 1 is pretty easy to meet IIRC. It's 2-4 that are hard, with pretty much no Level 4 certified ones on market I believe?
Yes: https://www.ibm.com/docs/en/cryptocards?topic=4768-overview
Re: Snowden leak: Cavium networking hardware may contain NSA backdoor
#425When I buy something electronic, my approach is "everything that is closed and goes online will be used to spy on people". It may seem a stretch, but governments can't exercise power over something they cannot control, and truly private communications would take away some of that control. To me there are no conspiracy theories or other strange reasons for being able to decrypt any seemingly private information except…
It's clear that they feel that way also. The engineer Andreas Spiess recently appeared in a briefing on dangerous, anarchy-enabling technologies simply for making a youtube video on an encrypted messaging protocol over lora mesh networking. They're carefully watching and cataloging any communications technology they can't compromise.
Re: Snowden leak: Cavium networking hardware may contain NSA backdoor
#426Earlier quoted context omitted.
crypto doesn't matter if chip itself has backdoor that will grant root access on some "magic" packet
Crypto matters for exactly this reason. All my internet traffic passes through unsafe middle-boxes, it is TLS and DH that make sure I can pass through untrusted middlemen without them knowing what is going on.
Re: Snowden leak: Cavium networking hardware may contain NSA backdoor
#427Earlier quoted context omitted.
Have you had the pleasure of working with Azure? I'll take AWS any day over that dumpster fire.
As someone that is deciding between AWS, Google and Azure - could give an outline of some of the Azure painpoints? Are there any blogs or other articles that outlines what your concerns would be? I'm pretty aware of how painful it can be to configure AWS well, IAM roles, the overly large eco-system that we won't need and unmitigated complexity to configure it all. It's not comforting to think Azure is worse yet.
The Azure Resource Manager system is much easier to use than the fragmented mess that is AWS.
The problem with Azure is that they’re still catching up to AWS. They have fewer products and the quality is worse.
Really basic issues will remain unaddressed for years.
Re: Snowden leak: Cavium networking hardware may contain NSA backdoor
#428Earlier quoted context omitted.
AWS support is pretty fucking terrible generally. We’re a very high rolling enterprise customer and it’s pretty obvious that some of their shit is being managed by two guys in a shed somewhere who don’t talk to each other.
As someone who was IN AWS premium support, I got the distinct impression they had no idea what they're doing I was a Linux Sysadmin for a decade. They initially hired me to work on the "BigData" support team Then after hiring threw me into CI/CD instead. I told them I don't know python or ruby and would be a terrible fit I asked if I can join the Linux team. EC2 is bread and butter, that's easy stuff "Oh we're actual…
Re: Snowden leak: Cavium networking hardware may contain NSA backdoor
#429Earlier quoted context omitted.
Chinese law requires Huawei to cooperate with their intelligence agencies.
That doesn't prove anything. You're just saying that Huawei could theoretically be compromised, but the above commenter asked for evidence.
Nobody has ever claimed that Huawei devices have backdoors. The issue is that the supply chain is compromised by legal means, not the hardware or software currently being shipped has technical vulnerabilities.
Re: Snowden leak: Cavium networking hardware may contain NSA backdoor
#430Earlier quoted context omitted.
If you're not under the threat cone of nation state surveillance (like trying to exfiltrate the radar-asborbing paint formula on the F35) then I wouldn't be too concerned. "That's not the point! It's about privacy!" Sure. I'll choose it ignore the fact that our civilization is somehow still functioning in a post-nuclear world.
100% agreed. If you’re concerned about privacy, being tracked online by corporations is a bigger concern than the the NSA. If you’re the target of an NSA investigation, you’re already fucked. Changing your network equipment is not going to help.