[flagged]
Snowden leak: Cavium networking hardware may contain NSA backdoor
521–530 of 628 posts
Re: Snowden leak: Cavium networking hardware may contain NSA backdoor
#522Looking more closely at this, the backdoor is almost certainly based on the back-doored random number generator, Dual_EC_DRBG, which is implemented as NIST SP 800-90A. From Wiki: >>> NIST SP 800-90A ("SP" stands for "special publication") is a publication by the National Institute of Standards and Technology with the title Recommendation for Random Number Generation Using Deterministic Random Bit Generators. The publ…
You are wildly incorrect here. The cryptographic module uses the CTR_DRBG, not the withdrawn Dual_EC_DRBG. The Dual_EC_DRBG was withdrawn in 2014, but this Security Policy for this module was submitted well past that for FIPS 140-2 revalidation, and the CMVP would not have let a testing lab submit it at all. This isn’t the back door.
Re: Snowden leak: Cavium networking hardware may contain NSA backdoor
#523The tweet seems to imply that the entire Ubiquiti Networks line of network hardware could be compromised. That's a shame; I was thinking of installing some in my house. I'm sure that Ubiquiti's customers will not be happy if they find out that the US Govt can access their private data.
Ubiquiti is all cloud based. If the government wants in to your auto-updating ubnt hardware, it's just a simple court order away. They don't need a backdoor.
I'm still using the access points, since I can run my own controller still, either virtualised in a container or VM, or a raspberry pi and you don't have to connect it to the cloud. I haven't found anything better, TP Link seem to have some interesting looking stuff but I worry about the security given they're based in Shenzhen...
1. https://shop.opnsense.com/product-categorie/hardware-applian...
Re: Snowden leak: Cavium networking hardware may contain NSA backdoor
#524Help me out here: if my network hardware is compromised, but all of my communication is encrypted, that leaves… traffic analysis? hoovering up the data and storing it to decrypt in the future when it becomes feasible? using the router as a foothold to attack the rest of my network? The first two are already happening for data that leaves my LAN. Unencrypted data on my LAN is vulnerable, and there is plenty of unencry…
I think I had read the three letter agency is storing this kind of data somewhere in a database for later technologies to decipher. So I’d assume they could snoop packets and store that data elsewhere. Whenever they harness quantum computing I could assume they put that stored data of yours through it and decrypt it all.
Re: Snowden leak: Cavium networking hardware may contain NSA backdoor
#525How the NSA successfully manage to prevent the Washington Post and friends from discovering and reporting on this malicious backdoor? They've been sitting on these documents for a decade. Are the journalists just that *uncurious* about the deep contents of the documents they hold exclusive access to? Was this some kind of organizational failing?
Are you kidding? WaPo serves the intelligence community. >After creation of the CIA in 1947, it enjoyed direct collaboration with many U.S. news organizations. But the agency faced a major challenge in October 1977, when—soon after leaving the Washington Post—famed Watergate reporter Carl Bernstein provided an extensive exposé in Rolling Stone. Citing CIA documents, Bernstein wrote that during the previous 25 years “…
There's a lot of pontificating about the virtuous, important, selfless job journalists do, but when they're manipulated to such an extent not just by the Government and intelligence agencies but also by their corporate sponsors... It's hard to not be a bit cynical...
Re: Snowden leak: Cavium networking hardware may contain NSA backdoor
#526Earlier quoted context omitted.
This reminds me of our own security team, who as far as I can tell do nothing but run POC's of new security tools. And then maybe once a year actually buy one, generating a ton of work (for others) to replace the very similar tool they bought last year. Seems like a good gig.
And the sad/funny thing is that said tool would probably do diddly squat if one employee falls for a social engineering/phishing attack.
Not to mention they may be another Crypto AG.
Re: Snowden leak: Cavium networking hardware may contain NSA backdoor
#527Earlier quoted context omitted.
Why would you need proof that it has been backdoored? The fact that it can be backdoored should be enough to disregard it for all uses right from the start.
The “need” for proof here determines whether there was likely malicious intent or negligence/ignorance. People who live in an evidence-based rational world don’t skip the evidence step and go straight to possibilities and counterfactuals.
An outcome of this is the requirement to treat all possibilities as certainties, regardless of evidence.
In this way, entire sections of industry will auto-assume the backdoor was both deliberate, and used both both friendlies & hostiles.
Re: Snowden leak: Cavium networking hardware may contain NSA backdoor
#528Ok the claim is the CPU was compromised and they were using ARM based tech. Is then ARM compromised? Cavium is now Marvell Technology.
ARM just licenses the ISA and provides some reference designs. Individual manufacturers can (and often do) add their own extensions and design the actual chips.
Re: Snowden leak: Cavium networking hardware may contain NSA backdoor
#529Just want to point out that iMessage makes a lot more sense in this regard. iMessage is that skeleton key that was requested years ago in San Beradino
What if that was theater?
Re: Snowden leak: Cavium networking hardware may contain NSA backdoor
#530Snowden also said Russia wasn't going to invade Ukraine in 2022.