Live data from Hacker News

Snowden leak: Cavium networking hardware may contain NSA backdoor

twitter.com

421–430 of 628 posts

Re: Snowden leak: Cavium networking hardware may contain NSA backdoor

#421
post #282

Earlier quoted context omitted.

> If your threat model includes... At my Fortune 250, our threat model apparently includes -- rather conveniently and coincidentally -- everything! Well, everything they make an off-the-shelf product for, anyway. It makes new purchasing decisions easy: "Does your product make any thing, in any way, more secure?" "Uh... Yes?" "You son of a bitch. We're in. Roll it out everywhere. Now."

Ahh, I've been there. I'm sure no concern is given for usability of the result. Welding your vault shut may make it harder for thieves to break in, but if your business model requires making deposits and withdrawals, it's somewhat less helpful.

Luckily, all but tiny portion of security products have a door you can open if you ask support nicely enough you didn’t know about before. So you can still get your stuff after you weld the door shut.

Re: Snowden leak: Cavium networking hardware may contain NSA backdoor

#422
post #30
post #24

[flagged]

Huawei stuff is proven to be compromised, just not by NSA, instead by China.

To my knowledge, no proof has actually been publicly presented for this claim. There have been a few stories that didn't pan out (like the one that boiled down to, "Huawei devices have telnet installed"), but no actual evidence of backdoors has come to light yet.

This is despite the fact that Huawei has been under an extraordinary level of scrutiny for years. British intelligence was given extensive access to Huawei's hardware and code, as a condition of Huawei equipment being installed in the UK. We know from Snowden that the NSA hacked into Huawei HQ, but there's no indication that they found any evidence of backdoors. And despite running a global campaign to convince/pressure other countries not to use Huawei, the US hasn't publicly unveiled any evidence of Huawei backdoors. British officials have even admitted that the UK's decision to ban Huawei was based on pressure from the US, not evidence of wrongdoing.[0,1] This all makes me think that the US, UK et al. don't actually have proof of backdoors.

0. https://www.theguardian.com/technology/2020/jul/18/pressure-...

1. https://www.euractiv.com/section/politics/short_news/uk-bann...

Re: Snowden leak: Cavium networking hardware may contain NSA backdoor

#423
post #376

Earlier quoted context omitted.

Ayup. We use AWS CloudHSM to hold our private signing keys for deploying field upgrades to our hardware. And when we break the CI scripts I see Cavium in the AWS logs. Now I gotta take this to our security team and figure out what to do.

Nothing? I mean, you are already in US-based cloud, so if NSA is interested, they will just request information directly, no backdoors needed. (This is a good test for your security team, btw: if they say anything other that "we do nothing", you know its all security theater)

But being able to request it and having a built-in backdoor for anyone with a key are different things. It has happened before that the Chinese government figured out network equipment backdoors that were put in for the US government. All your company secrets are there for the taking for anyone with the resources to figure out that backdoor. Especially now that people know it exists. Shouldn't this at least start the clock on expiring this hardware?

Re: Snowden leak: Cavium networking hardware may contain NSA backdoor

#424
post #368

Earlier quoted context omitted.

Google? Titan appears to meet FIPS 140-2 level 1. I find the levels bizarre. Chromebooks are highly exposed to physical attack. Keys in the cloud are not nearly as exposed. Yet people seem okay with level 1 for chromebooks but apparently want level 3 in the cloud? I’d rather see a level 1 or level 2 auditable cloud solution, with at least source available.

Level 1 is pretty easy to meet IIRC. It's 2-4 that are hard, with pretty much no Level 4 certified ones on market I believe?

The IBM one for z was level 4 I think..

Yes: https://www.ibm.com/docs/en/cryptocards?topic=4768-overview

Re: Snowden leak: Cavium networking hardware may contain NSA backdoor

#425

When I buy something electronic, my approach is "everything that is closed and goes online will be used to spy on people". It may seem a stretch, but governments can't exercise power over something they cannot control, and truly private communications would take away some of that control. To me there are no conspiracy theories or other strange reasons for being able to decrypt any seemingly private information except…

It's clear that they feel that way also. The engineer Andreas Spiess recently appeared in a briefing on dangerous, anarchy-enabling technologies simply for making a youtube video on an encrypted messaging protocol over lora mesh networking. They're carefully watching and cataloging any communications technology they can't compromise.

The guy's video was linked to from /r/SocialistRA and a screenshot of the link was included in a paper about "How Militant Anarcho-Socialist Networks Use Social Media to Instigate Widespread Violence Against Political Opponents and Law Enforcement." The paper never mentioned Spiess or meshtastic. What are we supposed to infer from that?

Re: Snowden leak: Cavium networking hardware may contain NSA backdoor

#426

Earlier quoted context omitted.

crypto doesn't matter if chip itself has backdoor that will grant root access on some "magic" packet

Crypto matters for exactly this reason. All my internet traffic passes through unsafe middle-boxes, it is TLS and DH that make sure I can pass through untrusted middlemen without them knowing what is going on.

If everything is encrypted then you're safe... until you decrypt the data on a machine with a backdoored CPU.

Re: Snowden leak: Cavium networking hardware may contain NSA backdoor

#427

Earlier quoted context omitted.

Have you had the pleasure of working with Azure? I'll take AWS any day over that dumpster fire.

As someone that is deciding between AWS, Google and Azure - could give an outline of some of the Azure painpoints? Are there any blogs or other articles that outlines what your concerns would be? I'm pretty aware of how painful it can be to configure AWS well, IAM roles, the overly large eco-system that we won't need and unmitigated complexity to configure it all. It's not comforting to think Azure is worse yet.

They’re just different. People like the devil they know.

The Azure Resource Manager system is much easier to use than the fragmented mess that is AWS.

The problem with Azure is that they’re still catching up to AWS. They have fewer products and the quality is worse.

Really basic issues will remain unaddressed for years.

Re: Snowden leak: Cavium networking hardware may contain NSA backdoor

#428
post #143

Earlier quoted context omitted.

AWS support is pretty fucking terrible generally. We’re a very high rolling enterprise customer and it’s pretty obvious that some of their shit is being managed by two guys in a shed somewhere who don’t talk to each other.

As someone who was IN AWS premium support, I got the distinct impression they had no idea what they're doing I was a Linux Sysadmin for a decade. They initially hired me to work on the "BigData" support team Then after hiring threw me into CI/CD instead. I told them I don't know python or ruby and would be a terrible fit I asked if I can join the Linux team. EC2 is bread and butter, that's easy stuff "Oh we're actual…

Thank you for this. Next time AWS try and tempt me over to them I’ll tell them literally fuck off. Not up for those games.

Re: Snowden leak: Cavium networking hardware may contain NSA backdoor

#429

Earlier quoted context omitted.

Chinese law requires Huawei to cooperate with their intelligence agencies.

That doesn't prove anything. You're just saying that Huawei could theoretically be compromised, but the above commenter asked for evidence.

They are compromised in terms of governance, and their legal environment is the proof of this.

Nobody has ever claimed that Huawei devices have backdoors. The issue is that the supply chain is compromised by legal means, not the hardware or software currently being shipped has technical vulnerabilities.

Re: Snowden leak: Cavium networking hardware may contain NSA backdoor

#430
post #240

Earlier quoted context omitted.

If you're not under the threat cone of nation state surveillance (like trying to exfiltrate the radar-asborbing paint formula on the F35) then I wouldn't be too concerned. "That's not the point! It's about privacy!" Sure. I'll choose it ignore the fact that our civilization is somehow still functioning in a post-nuclear world.

100% agreed. If you’re concerned about privacy, being tracked online by corporations is a bigger concern than the the NSA. If you’re the target of an NSA investigation, you’re already fucked. Changing your network equipment is not going to help.

On the contrary, changing equipment may actually help quite a bit when dealing with the NSA. The 2016 documentary "Zero Days" which was centered around the creation of Stuxnet showed that the NSA targeted specific hardware models to look for security holes. They had to buy matching hardware themselves and rigorously try to break it which took time and wasn't trivial to do
Post reply on HN