Earlier quoted context omitted.
It may be auto-updating by default, but that can be trivially disabled. Likewise, their cloud connectivity/management is optional. I'm running without issue multiple air-gapped Ubnt networks using their self-hosted controller software.
If it's airgapped, what do you care about it being backdoored?
Snowden leak: Cavium networking hardware may contain NSA backdoor
511–520 of 628 posts
Re: Snowden leak: Cavium networking hardware may contain NSA backdoor
#512Earlier quoted context omitted.
If, for example, SHA2 had a backdoor or a weakness known only to the NSA, then random contractors (like Snowden) could use that to extract money from the Bitcoin network, which uses SHA256 as its core cryptographic primitive. That's easily a billion dollar motivation right there, and I can't imagine a bunch of low-paid government drones resisting that cash prize. Everyone has a price. Hence, there's a level of trust…
I'm not advocating in either direction here, but let's assume backdoors like this do exist: Just because they haven't been abused doesn't mean that they wont in the future. Of the people I know that work with highly privileged materials, none would take advantage or abuse something like this, even with such a high payout. Even if they did, how would they continue to live comfortably? That said, it just takes one pers…
Re: Snowden leak: Cavium networking hardware may contain NSA backdoor
#513Looking more closely at this, the backdoor is almost certainly based on the back-doored random number generator, Dual_EC_DRBG, which is implemented as NIST SP 800-90A. From Wiki: >>> NIST SP 800-90A ("SP" stands for "special publication") is a publication by the National Institute of Standards and Technology with the title Recommendation for Random Number Generation Using Deterministic Random Bit Generators. The publ…
The cryptographic module uses the CTR_DRBG, not the withdrawn Dual_EC_DRBG. The Dual_EC_DRBG was withdrawn in 2014, but this Security Policy for this module was submitted well past that for FIPS 140-2 revalidation, and the CMVP would not have let a testing lab submit it at all.
This isn’t the back door.
Re: Snowden leak: Cavium networking hardware may contain NSA backdoor
#514The tweet seems to imply that the entire Ubiquiti Networks line of network hardware could be compromised. That's a shame; I was thinking of installing some in my house. I'm sure that Ubiquiti's customers will not be happy if they find out that the US Govt can access their private data.
I was also going to move to Ubiquiti but decided to go with Peplink instead based on recommendations from: https://routersecurity.org/ https://www.peplink.com/products/balance-20x/
Re: Snowden leak: Cavium networking hardware may contain NSA backdoor
#515The tweet seems to imply that the entire Ubiquiti Networks line of network hardware could be compromised. That's a shame; I was thinking of installing some in my house. I'm sure that Ubiquiti's customers will not be happy if they find out that the US Govt can access their private data.
Ubiquiti is all cloud based. If the government wants in to your auto-updating ubnt hardware, it's just a simple court order away. They don't need a backdoor.
Re: Snowden leak: Cavium networking hardware may contain NSA backdoor
#516Help me out here: if my network hardware is compromised, but all of my communication is encrypted, that leaves… traffic analysis? hoovering up the data and storing it to decrypt in the future when it becomes feasible? using the router as a foothold to attack the rest of my network? The first two are already happening for data that leaves my LAN. Unencrypted data on my LAN is vulnerable, and there is plenty of unencry…
So I’d assume they could snoop packets and store that data elsewhere. Whenever they harness quantum computing I could assume they put that stored data of yours through it and decrypt it all.
Re: Snowden leak: Cavium networking hardware may contain NSA backdoor
#517Earlier quoted context omitted.
still thinking… if the three-letter-agency has compromised the random number generator, then that means all traffic encrypted by the router may be easier to crack. What data is encrypted on the router? VPNs, for one. So a VPN, and all the plaintext traffic sent over it, could be made vulnerable.
>What data is encrypted on the router? VPNs, for one. What sort of VPN are we talking about?
Re: Snowden leak: Cavium networking hardware may contain NSA backdoor
#518[1] - https://www.electrospaces.net/2023/09/some-new-snippets-from...
[2] - https://pure.tue.nl/ws/portalfiles/portal/197416841/20220325...
Re: Snowden leak: Cavium networking hardware may contain NSA backdoor
#519Earlier quoted context omitted.
[flagged]
[flagged]
a.k.a. please don't feed the trolls
Re: Snowden leak: Cavium networking hardware may contain NSA backdoor
#520Earlier quoted context omitted.
Huawei stuff is proven to be compromised, just not by NSA, instead by China.
[flagged]
If you'd please review https://news.ycombinator.com/newsguidelines.html and stick to them when posting here, we'd appreciate it.