Live data from Hacker News

Snowden leak: Cavium networking hardware may contain NSA backdoor

twitter.com

531–540 of 628 posts

Re: Snowden leak: Cavium networking hardware may contain NSA backdoor

#531

Earlier quoted context omitted.

This is why security is not a "one size fits all" exercise. The first thing you must do is define your threat model. The reason the Chinese government doesn't want to build their telecom system on Cisco hardware is the same exact reason the USG doesn't want to do the same with Huawei hardware. Because neither government is delusional enough to think that parts/service/updates wouldn't be immediately sanctioned in tim…

> The US and China are already sanctioning each other's tech. It's not symmetrical. Since Trump, the US has been extraordinarily aggressive in its use of sanctions against Chinese companies, whereas China has been very reluctant to retaliate directly. The US has sanctioned hundreds of Chinese tech companies. China has only recently begun to retaliate in kind, but has so far only sanctioned a few US companies (Micron…

It isn't. And I didn't say it was. But the current state isn't the ultimate risk that is being considered. The ultimate risk is war, under which both the US and China would invoke defense powers to compel industry to act in their respective nations' interest, and would apply wide sanctions.

Re: Snowden leak: Cavium networking hardware may contain NSA backdoor

#532
post #510

Earlier quoted context omitted.

They are compromised in terms of governance, and their legal environment is the proof of this. Nobody has ever claimed that Huawei devices have backdoors. The issue is that the supply chain is compromised by legal means, not the hardware or software currently being shipped has technical vulnerabilities.

If you're using that non-standard definition of "compromised" then anything substantially made in the US, Australia, South Korea, Israel or Kazakhstan (non-exhaustive list) should be considered compromised. I'd love it if people actually stuck to some principles and stopped buying from any of these countries. But using that legal situation as a reason to single out China/Huawei is bullshit.

"compromised" might be a word used by the tech community to refer specifically to technical compromises, but the word means something much more broad outside of tech forums.

> then anything substantially made in the US, Australia, South Korea, Israel or Kazakhstan (non-exhaustive list) should be considered compromised.

Not really, because many of those countries you listed have mutual treaties of cooperation and are not hostile to each other.

Re: Snowden leak: Cavium networking hardware may contain NSA backdoor

#533
post #510

Earlier quoted context omitted.

If you're using that non-standard definition of "compromised" then anything substantially made in the US, Australia, South Korea, Israel or Kazakhstan (non-exhaustive list) should be considered compromised. I'd love it if people actually stuck to some principles and stopped buying from any of these countries. But using that legal situation as a reason to single out China/Huawei is bullshit.

"compromised" might be a word used by the tech community to refer specifically to technical compromises, but the word means something much more broad outside of tech forums. > then anything substantially made in the US, Australia, South Korea, Israel or Kazakhstan (non-exhaustive list) should be considered compromised. Not really, because many of those countries you listed have mutual treaties of cooperation and are…

> Not really, because many of those countries you listed have mutual treaties of cooperation and are not hostile to each other.

Doesn't seem to stop them from taking immensely hostile actions, e.g. the US spying on Merkel's emails, or helping killers and rapists who work for them evade arrest in "allied" countries. Governments are large and complex and have many competing interests. Why would/should one trust any of the ones I mentioned more than the government of China?

Re: Snowden leak: Cavium networking hardware may contain NSA backdoor

#534

Earlier quoted context omitted.

Why would you need proof that it has been backdoored? The fact that it can be backdoored should be enough to disregard it for all uses right from the start.

The “need” for proof here determines whether there was likely malicious intent or negligence/ignorance. People who live in an evidence-based rational world don’t skip the evidence step and go straight to possibilities and counterfactuals.

No, not really. If the data you hold is precious enough that you may have an actor with near infinite resources after you then you don't wait for proof to arrive, you assume the holes are there and act accordingly. Paranoia is fine if you have actual enemies, banking on the theory that evidence that a backdoor exists in a tool that you are using today will never surface is entirely the wrong approach.

Re: Snowden leak: Cavium networking hardware may contain NSA backdoor

#535

More interestingly, Cavium (now Marvell) also designed and manufactured the HSMs which are used by the top cloud providers (such as AWS, GCP, possibly Azure too), to hold the most critical private keys: https://www.prnewswire.com/news-releases/caviums-liquidsecur...

This breeds the familiar scenario where a group will start saying the link between the two is so clear that there must be a connection. Then you’ll get another group calling the first group conspiracy theorists, and say it’s just a coincidence of probability. Narrative control and information modeling is so powerful it’s scary.

Post Snowden the first group has some formidable ammunition.

Re: Snowden leak: Cavium networking hardware may contain NSA backdoor

#536
post #445

Earlier quoted context omitted.

> about how the Press played the part of the "fourth estate" as the Founders intended The rest of your post is quite the bullshit (easily probable with publicly accessible archives bullshit at that), but this is also wrong. The mythological god-like creatures that crafted America as their divine powers ordained it didn't "intend" for the press to be "the fourth power". That term was first used after the US revolution…

I have no idea what you're on about. The Founders of the US absolutely intended the press to be the last counterbalance on government overreach. It's literally why it's the First Amendment. Getting bogged down by terminology is perfect HN pedantry. Well done, sir!

Few counterpoints:

* it's an amendment, so not part of the original text

* "Congress shall make no law respecting an establishment of religion, or prohibiting the free exercise thereof; or abridging the freedom of speech, or of the press" . I don't know, it doesn't sound to me like the freedom of the press was the most pressing matter when that amendment was written considering the ordering, and again, the fact that it's an amendment and not part of the original text where the rest of the "checks and balances" are written.

Re: Snowden leak: Cavium networking hardware may contain NSA backdoor

#537
post #379

Earlier quoted context omitted.

It's not surprising because who wants to make their own FIPS 140-2 level 3 compliant key store device? Also, the Cavium one was the fastest one on the market the last time I looked at this. Thales, Safenet and IBM also had them..

Gotta be better than Utimaco HSM cards. I've worked with them, and have issues with them throwing false low power alarms, and wiping for no reason. And tech support is horrible, incompetent.

Wiping for no reason: that could well be a difference between the view of the firmware of the world versus your view and I guess they just decided to err on the side of caution?

And low power alarms may well be a variation on that theme. Glitching the power supply has been a tool in the arsenal of reverse engineers for a long time so that sort of sensitivity may well make sense. Voltage spikes and drops can be very short, short enough for you not to see them on a DVM but on a memory scope with a trigger value set much lower than you might expect they'd show up with alarming regularity in some hardware that I've worked on. And that explained some pretty weird instability issues. Good power is rare enough that really sensitive hardware usually has power conditioning circuitry right up close to the consumer.

Re: Snowden leak: Cavium networking hardware may contain NSA backdoor

#538
post #526

Earlier quoted context omitted.

And the sad/funny thing is that said tool would probably do diddly squat if one employee falls for a social engineering/phishing attack.

Occasionally security products turn into malware delivery platforms as well, because they run very privileged, are sometimes more shoddily developed than what they’re protecting, and have fewer eyeballs on them than the vanilla operating system. Not to mention they may be another Crypto AG.

> Occasionally

Much more frequently than that if you lump 'anti virus software' in with security products.

Re: Snowden leak: Cavium networking hardware may contain NSA backdoor

#539

Earlier quoted context omitted.

Are you kidding? WaPo serves the intelligence community. >After creation of the CIA in 1947, it enjoyed direct collaboration with many U.S. news organizations. But the agency faced a major challenge in October 1977, when—soon after leaving the Washington Post—famed Watergate reporter Carl Bernstein provided an extensive exposé in Rolling Stone. Citing CIA documents, Bernstein wrote that during the previous 25 years “…

I personally had my eyes opened during the run up to the Iraq war in 2022. Pretty much every single news org with national recognition seemed completely incapable of the smallest amount of critical thought. They would basically parrot the whitehouse/etc press releases, and never question a single thing in them. So, the behavior you point out is enabled by politicians who show such bad judgment in such a critical area…

Not sure if you meant 2002 instead of 2022 or Ukraine instead of Iraq. Either works!

Re: Snowden leak: Cavium networking hardware may contain NSA backdoor

#540

Earlier quoted context omitted.

The “need” for proof here determines whether there was likely malicious intent or negligence/ignorance. People who live in an evidence-based rational world don’t skip the evidence step and go straight to possibilities and counterfactuals.

There's a certain point in the security world where paranoia becomes a requirement, even though it only breeds more paranoia. An outcome of this is the requirement to treat all possibilities as certainties, regardless of evidence. In this way, entire sections of industry will auto-assume the backdoor was both deliberate, and used both both friendlies & hostiles.

Knowledge that this environment exists is also strong evidence that it was a backdoor.

If you propose a clearly questionable security practice in some arbitrary bureaucracy, the assumption is it's incompetence because that happens all the time and no one detects it until it's already in production.

If you propose a clearly questionable security practice to a cryptography standards body, the expectation is that you get laughed out of the room. Even the possibility of a backdoor would make everyone skeptical, which would be useless in a standard because no one would trust it.

And yet it made it through the standards process for some reason, but there is only one plausible reason.

Post reply on HN