Earlier quoted context omitted.
The agreement with the NSA is more likely like this: "if you don't comply, you will get arrested / fined for whatever reason (crypto exports issues or failure to comply with the law), maybe even by another authority, or journalists may discover your little things about X. If you comply we may help you with some tips occasionally to make sure our partnership is working well, or just not reveal your trade secrets to yo…
er...what? why do you think any of that has happened? we already saw this happen in public once with Qwest: https://www.eff.org/deeplinks/2007/10/qwest-ceo-nsa-punished...
Snowden leak: Cavium networking hardware may contain NSA backdoor
431–440 of 628 posts
Re: Snowden leak: Cavium networking hardware may contain NSA backdoor
#432Earlier quoted context omitted.
Huawei stuff is proven to be compromised, just not by NSA, instead by China.
[flagged]
The proof amounts to essentially one sentence spoken by an unnamed source
> U.S. officials said Huawei has built equipment that secretly preserves its ability to access networks through [lawful intercept interfaces]
but I understand that source confidentiality is useful so if WSJ trusts that, perhaps so should I. Not sure I'd then go so far as to independently say it has been "proven" when all that I truly know is that someone else believes someone else who has a commercial interest in saying this. It's probably true but that's not the same thing
Re: Snowden leak: Cavium networking hardware may contain NSA backdoor
#433Earlier quoted context omitted.
I wonder if MikroTik would be compromised- they’re Latvian and don’t necessarily have to bow to the NSA.
I assume by default that any hardware from any NATO nation is compromised by the NSA and other Western intelligence agencies. I also assume that any Chinese or Russian hardware is compromised by their respective intelligence agencies. And I assume that the NSA and other Western agencies are constantly trying to get backdoors into Chinese hardware (and I assume the Chinese are trying the do the same to ours). You're b…
Re: Snowden leak: Cavium networking hardware may contain NSA backdoor
#434Earlier quoted context omitted.
Where is the proof?
Chinese law requires Huawei to cooperate with their intelligence agencies.
It's a "pick your poison" situation, not a "they've got national security letters and so you can't trust them" one
Re: Snowden leak: Cavium networking hardware may contain NSA backdoor
#435Earlier quoted context omitted.
Have you had the pleasure of working with Azure? I'll take AWS any day over that dumpster fire.
As someone that is deciding between AWS, Google and Azure - could give an outline of some of the Azure painpoints? Are there any blogs or other articles that outlines what your concerns would be? I'm pretty aware of how painful it can be to configure AWS well, IAM roles, the overly large eco-system that we won't need and unmitigated complexity to configure it all. It's not comforting to think Azure is worse yet.
Re: Snowden leak: Cavium networking hardware may contain NSA backdoor
#436More interestingly, Cavium (now Marvell) also designed and manufactured the HSMs which are used by the top cloud providers (such as AWS, GCP, possibly Azure too), to hold the most critical private keys: https://www.prnewswire.com/news-releases/caviums-liquidsecur...
…which is really weird. At least Google and Microsoft are quite outspoken about their in-house secure element technology. If nothing else, at Google/Amazon scale, I’d be concerned about a third-party HSM losing data.
https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-faq-bas...
Re: Snowden leak: Cavium networking hardware may contain NSA backdoor
#437More interestingly, Cavium (now Marvell) also designed and manufactured the HSMs which are used by the top cloud providers (such as AWS, GCP, possibly Azure too), to hold the most critical private keys: https://www.prnewswire.com/news-releases/caviums-liquidsecur...
Ayup. We use AWS CloudHSM to hold our private signing keys for deploying field upgrades to our hardware. And when we break the CI scripts I see Cavium in the AWS logs. Now I gotta take this to our security team and figure out what to do.
The Intel Management Engine always runs as long as the motherboard is
receiving power, even when the computer is turned off. This issue can be
mitigated with deployment of a hardware device, which is able to disconnect
mains power.
Intel's main competitor AMD has incorporated the equivalent AMD Secure
Technology (formally called Platform Security Processor) in virtually all of
its post-2013 CPUs.
https://en.wikipedia.org/wiki/Intel_Management_Engine Ylian Saint-Hilaire, principal Engineer working on remote management software
including hardware manageability:
https://youtu.be/1seNMSamtxM?feature=sharedRe: Snowden leak: Cavium networking hardware may contain NSA backdoor
#438The tweet seems to imply that the entire Ubiquiti Networks line of network hardware could be compromised. That's a shame; I was thinking of installing some in my house. I'm sure that Ubiquiti's customers will not be happy if they find out that the US Govt can access their private data.
In a world where local PD can kick my door in, shoot me in the face, and the news will report that I had it coming because I own a gun, I find it hard to care that the IC can burn a technical access backdoor to access my private data.
Re: Snowden leak: Cavium networking hardware may contain NSA backdoor
#439Earlier quoted context omitted.
Chinese law requires Huawei to cooperate with their intelligence agencies.
As does the USA, so we shouldn't be using Windows or Yubico either, or virtually any other software/hardware from any other vendor because there's few countries that let you do illegal-over-there things without having a mechanism to force you It's a "pick your poison" situation, not a "they've got national security letters and so you can't trust them" one
The reason the Chinese government doesn't want to build their telecom system on Cisco hardware is the same exact reason the USG doesn't want to do the same with Huawei hardware. Because neither government is delusional enough to think that parts/service/updates wouldn't be immediately sanctioned in times of war.
The US and China are already sanctioning each other's tech. The risk of building critical infrastructure on it is obvious.
Re: Snowden leak: Cavium networking hardware may contain NSA backdoor
#440Earlier quoted context omitted.
Ubiquiti is all cloud based. If the government wants in to your auto-updating ubnt hardware, it's just a simple court order away. They don't need a backdoor.
It may be auto-updating by default, but that can be trivially disabled. Likewise, their cloud connectivity/management is optional. I'm running without issue multiple air-gapped Ubnt networks using their self-hosted controller software.