Live data from Hacker News

Snowden leak: Cavium networking hardware may contain NSA backdoor

twitter.com

541–550 of 628 posts

Re: Snowden leak: Cavium networking hardware may contain NSA backdoor

#541
post #376

Earlier quoted context omitted.

Nothing? I mean, you are already in US-based cloud, so if NSA is interested, they will just request information directly, no backdoors needed. (This is a good test for your security team, btw: if they say anything other that "we do nothing", you know its all security theater)

But being able to request it and having a built-in backdoor for anyone with a key are different things. It has happened before that the Chinese government figured out network equipment backdoors that were put in for the US government. All your company secrets are there for the taking for anyone with the resources to figure out that backdoor. Especially now that people know it exists. Shouldn't this at least start the…

Considering the scales of Amazon and Google, and their involvements with US government agencies in the US, I think it is fair to suspect that there is a lot we don't know about...

Re: Snowden leak: Cavium networking hardware may contain NSA backdoor

#544

Earlier quoted context omitted.

No, it's something that a bunch of old guys with issues told them helps their people. Beliefs stop when they are no longer about yourself but about how other people should live. Especially when those other people loudly protest that this is how you think they should be living. Killing them is just murder, not the spreading of ideas. But hey, those human rights are just for decoration anyway.

> it's something that a bunch of old guys with issues told them helps their people I don’t understand why you said “no” before this; I believe this agreed with what I’m saying.

We're back to what psychopathy is all about:

https://en.wikipedia.org/wiki/Psychopathy#Signs_and_symptoms

Re: Snowden leak: Cavium networking hardware may contain NSA backdoor

#545

Earlier quoted context omitted.

No, it's something that a bunch of old guys with issues told them helps their people. Beliefs stop when they are no longer about yourself but about how other people should live. Especially when those other people loudly protest that this is how you think they should be living. Killing them is just murder, not the spreading of ideas. But hey, those human rights are just for decoration anyway.

The old men persuade the would-be suicide bomber that educating women will liberate and liberalize them, and that this is counter to the interests of those who prefer the traditional order of society. Are they even lying?

Yes, they're lying.

The 'traditional order of society' is a society run by psycho pathological individuals and benefits nobody except for those individuals.

But you already knew that, didn't you?

Re: Snowden leak: Cavium networking hardware may contain NSA backdoor

#546
post #499
post #475

Earlier quoted context omitted.

Evil maid attack applies to data centers too doesn’t it?

Sure. But the attacker needs to actually get in, which is considerably harder than getting into a hotel room. But more relevantly, the kinds of countermeasures that get you from level 1 to a higher level don’t seem likely to help at all — if some evil-maids or otherwise fully compromises a machine hosting a FIPS 140-2 level 4 HSM, they likely get the unrestricted ability to perform cryptographic operations using keys…

> Sure. But the attacker needs to actually get in, which is considerably harder than getting into a hotel room.

It depends who is the attacker. There are countries (western democracies) where the police regularly "visits" datacenters.

Re: Snowden leak: Cavium networking hardware may contain NSA backdoor

#547
post #471

Looking more closely at this, the backdoor is almost certainly based on the back-doored random number generator, Dual_EC_DRBG, which is implemented as NIST SP 800-90A. From Wiki: >>> NIST SP 800-90A ("SP" stands for "special publication") is a publication by the National Institute of Standards and Technology with the title Recommendation for Random Number Generation Using Deterministic Random Bit Generators. The publ…

Is there any proof that Dual_EC_DRBG is backdoored? All I know is that Dual_EC_DRBG can be backdoored. And there are indeed suspicions, it was known from the start that not only Dual_EC_DRBG could be backdoored, but that it was rather weak to begin with. So, how could it be adopted as a standard? Now it seems that everyone takes the backdoor as a given. Is there any proof? Ideally the keys themselves (that would make…

Yes, yes there is: https://eprint.iacr.org/2015/767.pdf

Re: Snowden leak: Cavium networking hardware may contain NSA backdoor

#548
post #522

Earlier quoted context omitted.

You are wildly incorrect here. The cryptographic module uses the CTR_DRBG, not the withdrawn Dual_EC_DRBG. The Dual_EC_DRBG was withdrawn in 2014, but this Security Policy for this module was submitted well past that for FIPS 140-2 revalidation, and the CMVP would not have let a testing lab submit it at all. This isn’t the back door.

Irrelevant. This "revelation" is from pre-2013 information. Dual_EC may have been the capability before it was withdrawn.

> Irrelevant Except it was relevant as a response to the OP in that: I was pointing out their conflation of two different DRBGs.

Having an SP 800-90A DRBG does not mean you support all of them, nor does it imply the user could change between the 3 (or, in that hypothetical, 4).

Outside of that, it is unlikely that this module had Dual_EC_DRBG at any point in time for three reasons: 1) Submitting a hardware module that has an entirely new DRBG would require a lot of low level work from Cavium, and the modifications made to the physical module would likely constitute more than an updated certificate (i.e., a new certificate). 2) Even though the DRBG was withdrawn, the CAVP lists algorithm certificates, and this includes historic certificates. Cavium doesn’t have a Dual_EC_DRBG certificate for any operating environment. A list of Dual_EC_DRBG certificates can be seen here: https://csrc.nist.gov/projects/cryptographic-algorithm-valid... 3) the earliest security policy for the module that I could find dates back to 07/22/2014, and it still uses the CTR_DRBG. Security policy here: https://csrc.nist.rip/groups/STM/cmvp/documents/140-1/140sp/...

Re: Snowden leak: Cavium networking hardware may contain NSA backdoor

#549

Earlier quoted context omitted.

> The US and China are already sanctioning each other's tech. It's not symmetrical. Since Trump, the US has been extraordinarily aggressive in its use of sanctions against Chinese companies, whereas China has been very reluctant to retaliate directly. The US has sanctioned hundreds of Chinese tech companies. China has only recently begun to retaliate in kind, but has so far only sanctioned a few US companies (Micron…

It isn't. And I didn't say it was. But the current state isn't the ultimate risk that is being considered. The ultimate risk is war, under which both the US and China would invoke defense powers to compel industry to act in their respective nations' interest, and would apply wide sanctions.

The zero-sum thinking of the Trump and Biden administrations, in which China is seen purely as a threat and all sorts of cooperation and economic integration are being rolled back, makes war more likely. The US is not compelled to ban Huawei and sanction all sorts of Chinese tech firms - that's a choice.

Re: Snowden leak: Cavium networking hardware may contain NSA backdoor

#550
post #379

Earlier quoted context omitted.

Gotta be better than Utimaco HSM cards. I've worked with them, and have issues with them throwing false low power alarms, and wiping for no reason. And tech support is horrible, incompetent.

Wiping for no reason: that could well be a difference between the view of the firmware of the world versus your view and I guess they just decided to err on the side of caution? And low power alarms may well be a variation on that theme. Glitching the power supply has been a tool in the arsenal of reverse engineers for a long time so that sort of sensitivity may well make sense. Voltage spikes and drops can be very s…

Wiping for no reason: that could well be a difference between the view of the firmware of the world versus your view and I guess they just decided to err on the side of caution?

No. I said I've been in touch with technical support, and the manuals, docs, and their support is clear. It should not be wiping, it has a backuo battery too.

We've spent hours and hours testing, to validate the issue, and cause.

They likely have a firmware bug, or bad board design. And we've seen this from cards from different batches, bought years apart.

Their support is incompetent, and I say that with 30+ years of dealing with, and providing tech support. They fail to read tickets, and even spend (supposedly) weeks running tests, while ignoring vital data in tickets, and conveyed in support calls.

They. Are. Incompetent.

In terms of "issues with power", no. Not over dozens of servers, in different datacentres, and even just with the card at rest, out of server, on battery.

Understand, their job is to provide stable. HSM cards are useless, if they randomly wipe when in use, while under power "just cause".

I find it weird that you're playing devil's advocate here, describing how hard this is, this is an enterprise grade card, and people have been making reliable, and safe HSMs for decades.

The problem is 100% them, their desogn.

And even more so, their incompetent tech support.

Did I mention their tech support is incompetent?

Post reply on HN