Earlier quoted context omitted.
Ayup. We use AWS CloudHSM to hold our private signing keys for deploying field upgrades to our hardware. And when we break the CI scripts I see Cavium in the AWS logs. Now I gotta take this to our security team and figure out what to do.
Nobody cares. If caring gets in the way of easy money. Spoiler...it does.
Snowden leak: Cavium networking hardware may contain NSA backdoor
551–560 of 628 posts
Re: Snowden leak: Cavium networking hardware may contain NSA backdoor
#552Earlier quoted context omitted.
I'd be surprised if you get anything more than generic statements about how they take security very seriously and they are open to suggestions, but avoid addressing the mentioned concerns directly (and this applies to all cloud providers out there, not just AWS). I'm sure a few others here would like to see their response as well.
wouldnt such a backdoor invalidate all promises made by external audits e.g. https://cloud.google.com/security/compliance/offerings and more importantly wouldn't it violate safe harbor agreement with the EU or whatever sham this safe-harbor was replaced with?
Re: Snowden leak: Cavium networking hardware may contain NSA backdoor
#553Earlier quoted context omitted.
“I can handle of people”? Cannot parse.
I think that was a mobile typo. The quote is just "I can handle people"
mixing the two implicates humans for the errors of machines
edit:
unless failure to disable autocorrect is counted as a user error
Re: Snowden leak: Cavium networking hardware may contain NSA backdoor
#554Earlier quoted context omitted.
This reminds me of our own security team, who as far as I can tell do nothing but run POC's of new security tools. And then maybe once a year actually buy one, generating a ton of work (for others) to replace the very similar tool they bought last year. Seems like a good gig.
And the sad/funny thing is that said tool would probably do diddly squat if one employee falls for a social engineering/phishing attack.
They gave me a laptop with 8gb of ram. The laptop runs invisible security software that nominally takes 6~6.8gb.
We just got penetrated by two attackers in the last 40 days.
Re: Snowden leak: Cavium networking hardware may contain NSA backdoor
#555Earlier quoted context omitted.
This breeds the familiar scenario where a group will start saying the link between the two is so clear that there must be a connection. Then you’ll get another group calling the first group conspiracy theorists, and say it’s just a coincidence of probability. Narrative control and information modeling is so powerful it’s scary.
Post Snowden the first group has some formidable ammunition.
Re: Snowden leak: Cavium networking hardware may contain NSA backdoor
#556For anyone wondering "what's the big deal" it's worth remembering the NSA has a bad track record of keeping their own hacking tools secure. https://en.wikipedia.org/wiki/The_Shadow_Brokers It infuriates me the NSA actively works to undermine American security. Their brief is to protect us, not plant backdoors and then lose the keys.
It infuriates me that the NSA actively works to undermine International security.
Seriously.
Re: Snowden leak: Cavium networking hardware may contain NSA backdoor
#557Looking more closely at this, the backdoor is almost certainly based on the back-doored random number generator, Dual_EC_DRBG, which is implemented as NIST SP 800-90A. From Wiki: >>> NIST SP 800-90A ("SP" stands for "special publication") is a publication by the National Institute of Standards and Technology with the title Recommendation for Random Number Generation Using Deterministic Random Bit Generators. The publ…
This doesn't have to be backdoored.
It could simply be a bug in their hardware RNG that uses something that isn't public to break it.
Or something that Cavium did not realise was vulnerable.
Re: Snowden leak: Cavium networking hardware may contain NSA backdoor
#558Earlier quoted context omitted.
I doubt Russia cared much about a cancelled US passport. If they felt he was not worth something to them they would have made sure he was out of Russia. Personally I don't think it was intentional on his part to get stuck in Russia, just a bad error. But he is certainly living there by their "good will" now, and it shows in his public behaviour.
Russia may not care (doubtful), but the airline will not even let you board . Not trashing your host is probably wise, but given his experience with the US government, he probably no longer subscribes to the naive worldview that Putin (or Xi) are uniquely bad, just bad in their own ways and responding to the world with their nation's interests (and their legacies) in mind.
The fact Snowden is still alive pushing anti-US propaganda shows the difference, if the roles were reversed he would have been assassinated long ago.
Re: Snowden leak: Cavium networking hardware may contain NSA backdoor
#559If you have the chip, you can find the backdoor... if you cannot find it, you can't conclude its actually there. There's ways to analyse chips to see if they are backdoored. Decapping, fuzzing and whatnot. Simply basing such of a conclusion from a few lines in a document seems a bit off to me...
Did anyone actually find the thing??
Re: Snowden leak: Cavium networking hardware may contain NSA backdoor
#560Earlier quoted context omitted.
And the sad/funny thing is that said tool would probably do diddly squat if one employee falls for a social engineering/phishing attack.
As someone who's company just suffered this exact issue, all I can say is yes. They gave me a laptop with 8gb of ram. The laptop runs invisible security software that nominally takes 6~6.8gb. We just got penetrated by two attackers in the last 40 days.
* that you know of