Earlier quoted context omitted.
Why would you need proof that it has been backdoored? The fact that it can be backdoored should be enough to disregard it for all uses right from the start.
Trusting Trust says everything could be backdoored, but somehow I'm guessing you still use computers.
Snowden leak: Cavium networking hardware may contain NSA backdoor
491–500 of 628 posts
Re: Snowden leak: Cavium networking hardware may contain NSA backdoor
#492Earlier quoted context omitted.
> Is there any proof that Dual_EC_DRBG is backdoored? The algorithm is bad: it's complicated and slow. The competing algorithms were much simpler, much more secure by construction, and much faster. Most importantly, there was no obvious way to backdoor the competing algorithms, but there's a hilariously trivial way to backdoor Dual_EC_DRBG. Ergo: the only reason you would ever devise or use Dual_EC_DRBG is to introdu…
Why would you need proof that it has been backdoored? The fact that it can be backdoored should be enough to disregard it for all uses right from the start.
With Dual_EC_DRBG, everyone knew that it could be back doored. It's not some guess, or "maybe it could have". It was obviously designed to be back doored. It should have been called "NSA_BACKDOOR_RNG", because that's literally what it is.
And yes, all organisations that are not under the thumb of the US Government laughed at the transparent attempt to introduce a back door and rejected Dual_EC_DRBG. Only US-based companies use it, which ought to give you a hint.
Re: Snowden leak: Cavium networking hardware may contain NSA backdoor
#493Earlier quoted context omitted.
> Is there any proof that Dual_EC_DRBG is backdoored? The algorithm is bad: it's complicated and slow. The competing algorithms were much simpler, much more secure by construction, and much faster. Most importantly, there was no obvious way to backdoor the competing algorithms, but there's a hilariously trivial way to backdoor Dual_EC_DRBG. Ergo: the only reason you would ever devise or use Dual_EC_DRBG is to introdu…
Why would you need proof that it has been backdoored? The fact that it can be backdoored should be enough to disregard it for all uses right from the start.
People who live in an evidence-based rational world don’t skip the evidence step and go straight to possibilities and counterfactuals.
Re: Snowden leak: Cavium networking hardware may contain NSA backdoor
#494I don’t know much about security, especially at the hardware level. However, I have a question for those of you that do. Suppose you were given a healthy budget, a team, and a few years. Would you be able to build network hardware that did not contain back doors? How healthy would the budget need to be? How skilled would the team need to be? I assume you’d have to assume most external vendors are compromised and rebu…
If you care about performance, then you need to start by building a fab. $100B+, and you’ll end up with government moles.
So, I assume you don’t care about performance. If you keep stuff under 100MHz or so, then you can avoid complicated signal processing.
Design for a old process, and tape out. Now, read up on decapping and reverse engineering old dies with garage-built microscopes.
Make many copies of your chips, then decap a random sample and verify they are to spec by hand. Use the rest to build a computer that can verify the output of the microscope.
You can print circuit boards using hobbyist kits on a laser printer. Since they are 1 or 2 sided, you can visually verify them.
If you can find commercially available chips that are primitive enough for you to decap, scan, reverse engineer and verify, then use those instead (following the random destructive sampling procedure above).
Good luck!
Re: Snowden leak: Cavium networking hardware may contain NSA backdoor
#495Re: Snowden leak: Cavium networking hardware may contain NSA backdoor
#496Earlier quoted context omitted.
Why would you need proof that it has been backdoored? The fact that it can be backdoored should be enough to disregard it for all uses right from the start.
Trusting Trust says everything could be backdoored, but somehow I'm guessing you still use computers.
That's easily a billion dollar motivation right there, and I can't imagine a bunch of low-paid government drones resisting that cash prize. Everyone has a price.
Hence, there's a level of trust that can be gained through observation of failures to abuse backdoors. If they don't exist, they can't be abused. If they exist, then they must be used/abused, otherwise what's the point? Such usage will be eventually discovered. E.g.: The use of the Dual_EC_DRBG back-door to tap into Juniper VPN connections by the Chinese government was discovered and made public.
Re: Snowden leak: Cavium networking hardware may contain NSA backdoor
#497Re: Snowden leak: Cavium networking hardware may contain NSA backdoor
#498Earlier quoted context omitted.
The casual nature of stating a completely impossible conspiracy theory has been common place online for years, HN news used to be immune. It's illegal for FBI or CIA to actively target a US company. Anyone doing so would be fired for cause.
It's illegal to lie under oath to Congress, did James Clapper go to jail? It's illegal to sleep with underage girls, how many people on Epstein's client list went to jail?
Does that make sense to you? It doesn't to me.
Re: Snowden leak: Cavium networking hardware may contain NSA backdoor
#499Earlier quoted context omitted.
This is so weird. The idea of an adversary covertly walking off with an IBM Mainframe or covertly bringing an electronics lab, a microscope, logic analyzers, glitching hardware, etc to the aforementioned mainframe is rather strange. Whereas someone doing that to a phone or a laptop or a game console is very likely. If I wanted to store an important long term key in a secure facility, I would worry, first and foremost…
Evil maid attack applies to data centers too doesn’t it?
Now if someone evil-maid attacks the HSM itself, that’s a different story. Any good HSM should resist this, especially one found in a portable device. And this is because you can steal an entire important corporate laptop or other portable device without necessarily raising an quick alarm, whereas I have trouble imagining someone walking off with the HSM out of an IBM mainframe or with an AWS HSM without the loss being noticed immediately.
(To be fair, in the mainframe case, some crusty corporations seem to have a remarkable ability to fail to notice obvious crypto problems like their public facing certificates expiring. But a loss of an entire HSM from a secure large cloud datacenter will, at the very least, immediately trigger “elevated failure rates” or whatever they like to call it…)
Re: Snowden leak: Cavium networking hardware may contain NSA backdoor
#500How the NSA successfully manage to prevent the Washington Post and friends from discovering and reporting on this malicious backdoor? They've been sitting on these documents for a decade. Are the journalists just that *uncurious* about the deep contents of the documents they hold exclusive access to? Was this some kind of organizational failing?
Are you kidding? WaPo serves the intelligence community. >After creation of the CIA in 1947, it enjoyed direct collaboration with many U.S. news organizations. But the agency faced a major challenge in October 1977, when—soon after leaving the Washington Post—famed Watergate reporter Carl Bernstein provided an extensive exposé in Rolling Stone. Citing CIA documents, Bernstein wrote that during the previous 25 years “…
So, the behavior you point out is enabled by politicians who show such bad judgment in such a critical area, and yet few if any lost their positions over their votes. I personalty have been wondering for the past few years how many of our leaders are actually there of their own accord, rather than put there by various backroom cabals of business leaders and intelligence (foreign and domestic) agencies that want to put their thumbs on the scale with a representative or dozen. How would you ever know, except by their behavior.