Live data from Hacker News

Snowden leak: Cavium networking hardware may contain NSA backdoor

twitter.com

551–560 of 628 posts

Re: Snowden leak: Cavium networking hardware may contain NSA backdoor

#551

Earlier quoted context omitted.

Ayup. We use AWS CloudHSM to hold our private signing keys for deploying field upgrades to our hardware. And when we break the CI scripts I see Cavium in the AWS logs. Now I gotta take this to our security team and figure out what to do.

Nobody cares. If caring gets in the way of easy money. Spoiler...it does.

future you will care and facepalm

Re: Snowden leak: Cavium networking hardware may contain NSA backdoor

#552

Earlier quoted context omitted.

I'd be surprised if you get anything more than generic statements about how they take security very seriously and they are open to suggestions, but avoid addressing the mentioned concerns directly (and this applies to all cloud providers out there, not just AWS). I'm sure a few others here would like to see their response as well.

wouldnt such a backdoor invalidate all promises made by external audits e.g. https://cloud.google.com/security/compliance/offerings and more importantly wouldn't it violate safe harbor agreement with the EU or whatever sham this safe-harbor was replaced with?

As you say, a sham : as long as the Patriot Act is still effectively ongoing, everyone else is still trying really hard to look the other way, (especially while the war is still ongoing !), ignoring the CJUE, which has no choice but to shoot down one agreement after another, since they automatically violate the EU Charter of Fundamental Rights : https://en.wikipedia.org/wiki/Max_Schrems#Schrems_I

Re: Snowden leak: Cavium networking hardware may contain NSA backdoor

#553
post #236

Earlier quoted context omitted.

“I can handle of people”? Cannot parse.

I think that was a mobile typo. The quote is just "I can handle people"

i feel like "typo" should mean "typing error" and not "autocorrect fubar"

mixing the two implicates humans for the errors of machines

edit:

unless failure to disable autocorrect is counted as a user error

Re: Snowden leak: Cavium networking hardware may contain NSA backdoor

#554

Earlier quoted context omitted.

This reminds me of our own security team, who as far as I can tell do nothing but run POC's of new security tools. And then maybe once a year actually buy one, generating a ton of work (for others) to replace the very similar tool they bought last year. Seems like a good gig.

And the sad/funny thing is that said tool would probably do diddly squat if one employee falls for a social engineering/phishing attack.

As someone who's company just suffered this exact issue, all I can say is yes.

They gave me a laptop with 8gb of ram. The laptop runs invisible security software that nominally takes 6~6.8gb.

We just got penetrated by two attackers in the last 40 days.

Re: Snowden leak: Cavium networking hardware may contain NSA backdoor

#555

Earlier quoted context omitted.

This breeds the familiar scenario where a group will start saying the link between the two is so clear that there must be a connection. Then you’ll get another group calling the first group conspiracy theorists, and say it’s just a coincidence of probability. Narrative control and information modeling is so powerful it’s scary.

Post Snowden the first group has some formidable ammunition.

Now apply that to every other "conspiracy.."

Re: Snowden leak: Cavium networking hardware may contain NSA backdoor

#556

For anyone wondering "what's the big deal" it's worth remembering the NSA has a bad track record of keeping their own hacking tools secure. https://en.wikipedia.org/wiki/The_Shadow_Brokers It infuriates me the NSA actively works to undermine American security. Their brief is to protect us, not plant backdoors and then lose the keys.

>It infuriates me the NSA actively works to undermine American security.

It infuriates me that the NSA actively works to undermine International security.

Seriously.

Re: Snowden leak: Cavium networking hardware may contain NSA backdoor

#557

Looking more closely at this, the backdoor is almost certainly based on the back-doored random number generator, Dual_EC_DRBG, which is implemented as NIST SP 800-90A. From Wiki: >>> NIST SP 800-90A ("SP" stands for "special publication") is a publication by the National Institute of Standards and Technology with the title Recommendation for Random Number Generation Using Deterministic Random Bit Generators. The publ…

> Looking more closely at this, the backdoor is almost certainly based on the back-doored random number generator, Dual_EC_DRBG, which is implemented as NIST SP 800-90A.

This doesn't have to be backdoored.

It could simply be a bug in their hardware RNG that uses something that isn't public to break it.

Or something that Cavium did not realise was vulnerable.

Re: Snowden leak: Cavium networking hardware may contain NSA backdoor

#558

Earlier quoted context omitted.

I doubt Russia cared much about a cancelled US passport. If they felt he was not worth something to them they would have made sure he was out of Russia. Personally I don't think it was intentional on his part to get stuck in Russia, just a bad error. But he is certainly living there by their "good will" now, and it shows in his public behaviour.

Russia may not care (doubtful), but the airline will not even let you board . Not trashing your host is probably wise, but given his experience with the US government, he probably no longer subscribes to the naive worldview that Putin (or Xi) are uniquely bad, just bad in their own ways and responding to the world with their nation's interests (and their legacies) in mind.

This is a fun narrative that the US is just the same as the Russian or Chinese governments, i wonder who could benefit from pushing that...

The fact Snowden is still alive pushing anti-US propaganda shows the difference, if the roles were reversed he would have been assassinated long ago.

Re: Snowden leak: Cavium networking hardware may contain NSA backdoor

#559
Didn't read all the leaks but it seems a bit wild to conclude a vendor implemented a backdoor purposefully. There's some been found ofcourse, but simply being SIGINT capable, why does that imply 'backdoor'.? If they have a nice exploit for the device it would also make it SIGINT capable no? without the vendor's cooperation (apart perhaps from a buggy implementation.)

If you have the chip, you can find the backdoor... if you cannot find it, you can't conclude its actually there. There's ways to analyse chips to see if they are backdoored. Decapping, fuzzing and whatnot. Simply basing such of a conclusion from a few lines in a document seems a bit off to me...

Did anyone actually find the thing??

Re: Snowden leak: Cavium networking hardware may contain NSA backdoor

#560

Earlier quoted context omitted.

And the sad/funny thing is that said tool would probably do diddly squat if one employee falls for a social engineering/phishing attack.

As someone who's company just suffered this exact issue, all I can say is yes. They gave me a laptop with 8gb of ram. The laptop runs invisible security software that nominally takes 6~6.8gb. We just got penetrated by two attackers in the last 40 days.

> We just got penetrated by two attackers in the last 40 days.

* that you know of

Post reply on HN