Live data from Hacker News

Snowden leak: Cavium networking hardware may contain NSA backdoor

twitter.com

461–470 of 628 posts

Re: Snowden leak: Cavium networking hardware may contain NSA backdoor

#461

Earlier quoted context omitted.

> But now I'm thinking: Is it better that the US is spying on me in Europe, vs. having EU governments do it? I feel like I'd be somewhat more safe from the US, compared to if my own government decides to spy on me. https://en.wikipedia.org/wiki/Five_Eyes > In recent years, documents of the FVEY have shown that they are intentionally spying on one another's citizens and sharing the collected information with each othe…

None of these are EUropean countries.

Scroll down and learn about FVEY+3 and friends.

Re: Snowden leak: Cavium networking hardware may contain NSA backdoor

#462

More interestingly, Cavium (now Marvell) also designed and manufactured the HSMs which are used by the top cloud providers (such as AWS, GCP, possibly Azure too), to hold the most critical private keys: https://www.prnewswire.com/news-releases/caviums-liquidsecur...

[deleted]

Re: Snowden leak: Cavium networking hardware may contain NSA backdoor

#463
post #355

Earlier quoted context omitted.

Some specific Ubiquiti gear uses Cavium SOCs, but certainly not all. The UDM Pro uses an Annapurna Labs SOC and my old EdgeRouter-X was Mediatek.

Unifi stuff auto updates from the vendor, which is subject to US law. The SoC manufacturer is irrelevant. If the USG wants in, it's just a click away in any case.

If the USG wants in, it's just a click away in any case.

What's a legal and practical mechanism the US Government could use to do this? In almost any number of clicks, never mind one.

Re: Snowden leak: Cavium networking hardware may contain NSA backdoor

#466

When I buy something electronic, my approach is "everything that is closed and goes online will be used to spy on people". It may seem a stretch, but governments can't exercise power over something they cannot control, and truly private communications would take away some of that control. To me there are no conspiracy theories or other strange reasons for being able to decrypt any seemingly private information except…

[deleted]

Re: Snowden leak: Cavium networking hardware may contain NSA backdoor

#467
post #103

Earlier quoted context omitted.

Leaving out the extortion part makes it very hard to read your comment as being made in good faith.

Learn about Qwest if you think NSA doesn't also extort to get what they want: https://www.eff.org/deeplinks/2007/10/qwest-ceo-nsa-punished...

Oh, I remember when that first came out. I’m not defending the NSA but criticizing the idea that it’s somehow unfair for some dude to go to jail for trying to extort his former employer. The NSA misconduct is a much less clear-cut question of Congressional approval and oversight - similar to how it’s not as simple as a murder charge when a soldier is accused of a war crime.

Re: Snowden leak: Cavium networking hardware may contain NSA backdoor

#468
post #30
post #24

[flagged]

Huawei stuff is proven to be compromised, just not by NSA, instead by China.

Proven?

Did they ever show any evidence?

I hear that claim pretty often but have never seen any proof unlike in Cisco hardware.

Re: Snowden leak: Cavium networking hardware may contain NSA backdoor

#469
post #205
post #185

Earlier quoted context omitted.

I generally hold a similar opinion. However I have two data points that suggests back-doors are not available by default (for my government at least), but that they are aggressively bugging (or auditing, lol) devices: * When I ordered the first generation Raspberry Pi, they were stuck in the toll a long time, and when they arrived all the warranty seals were broken. Consequently I never really used them. * When I ord…

I just assume I'm not interested enough to be spied upon by randoms > When I ordered the first generation Raspberry Pi, they were stuck in the toll a long time, and when they arrived all the warranty seals were broken. Consequently I never really used them. If state have means to bug raspberry pi it has means to re-seal the box...

As we learned from Snowden, they spy ob everyone they just don't look in every data point but they still collect everything they can get.

Re: Snowden leak: Cavium networking hardware may contain NSA backdoor

#470
post #30

Earlier quoted context omitted.

Huawei stuff is proven to be compromised, just not by NSA, instead by China.

[flagged]

I would trust a proven security research group's analysis and evidence of backdoors rather than CNN or WSJ that has a track record of lies and biases. They always cite government sources or experts without provided a single shred of evidence. I have read a lot of articles in relations to the so called "Chinese backdoor" and the "evidence" was either the equipment contains default root or admin passwords or the software has vulnerabilities. Last time I checked, most if not all vendors have default admin accounts and passwords so you can configure the device and change the initial password. Similarly I have not come across any network equipment software without security vulnerabilities. If you can refer me to an article with conclusive evidence please send me the link. This would be much appreciated.
Post reply on HN