Live data from Hacker News

Snowden leak: Cavium networking hardware may contain NSA backdoor

twitter.com

621–628 of 628 posts

Re: Snowden leak: Cavium networking hardware may contain NSA backdoor

#621

Earlier quoted context omitted.

Sure, so you hit all of the people that have all of the pieces. Problem solved.

Or you publicly announce you're hitting 1 of the N people with the rubber hose until M-1 of the other people send you their key fragments. It's not like these keys are shared among disinterested strangers who have no attachment to each other.

Somehow, somewhere you've just influenced a megacorp's internal crypto process.

Re: Snowden leak: Cavium networking hardware may contain NSA backdoor

#622

Looking more closely at this, the backdoor is almost certainly based on the back-doored random number generator, Dual_EC_DRBG, which is implemented as NIST SP 800-90A. From Wiki: >>> NIST SP 800-90A ("SP" stands for "special publication") is a publication by the National Institute of Standards and Technology with the title Recommendation for Random Number Generation Using Deterministic Random Bit Generators. The publ…

Sorry, what does it even mean for a random number generator to have a backdoor? Is it leaking your generated keys to the NSA? Does it have some arbitrary code execution vulnerability?

Re: Snowden leak: Cavium networking hardware may contain NSA backdoor

#623
post #6

The tweet seems to imply that the entire Ubiquiti Networks line of network hardware could be compromised. That's a shame; I was thinking of installing some in my house. I'm sure that Ubiquiti's customers will not be happy if they find out that the US Govt can access their private data.

okay, so assuming the US gov can access my private LAN data due to my use of the Ubiquiti USG as router/firewall, USG wifi APs etc, of what form would this data exfiltration take? can we please explore/explain how this "compromise" would happen in real-life. if i were sniffing for outbound WAN traffic as root on the unix-like that the USG run, would i see the exfiltration traffic? or is this [supposedly/apparently] h…

Would be an interesting experiment to see what an oscilloscope sees on the wire vs what tcpdump records... There was a story somewhere on the net where someone complained thay they wanted to include a do not record payload parameter in tcpdump and couldn't get it through.

Re: Snowden leak: Cavium networking hardware may contain NSA backdoor

#624
post #590

Earlier quoted context omitted.

Airgapped doesn't necessarily mean it can't be accessed remotely...

That's literally and precisely what it means. Perhaps there is some new watered down usage (like what happened to "literally" or "bricked") but that is precisely why people use the term "air-gapped" - to denote networks with PHYSICAL separation from other means of access. (Of course, if you connect an AP, it's no longer air-gapped."

All your computers are plugged into the mains for electricity... Always, always the thing that's ubiqutious is the perfect entrance for the oppressors, since noone suspects anything about those innocent things.

Re: Snowden leak: Cavium networking hardware may contain NSA backdoor

#625
post #509

Earlier quoted context omitted.

There is ample evidence of China's intentions and capability to install backdoors. Everything made in China or a heavily influenced Chinese country should be assumed to be compromised, even if 'proven' otherwise. Chances are we just haven't found the backdoor yet.

Sure - but all that is equally true of the US.

True of the US yes. Equally? I probably wouldn't say that. The US govt doesn't have the same control over media the the Chinese govt has. So they have to work harder to keep things out of public view. The US also has to massage the way they work to be somewhat within the bounds of the constitution.

Re: Snowden leak: Cavium networking hardware may contain NSA backdoor

#626

Earlier quoted context omitted.

This breeds the familiar scenario where a group will start saying the link between the two is so clear that there must be a connection. Then you’ll get another group calling the first group conspiracy theorists, and say it’s just a coincidence of probability. Narrative control and information modeling is so powerful it’s scary.

Now get yourself some half-decent psyops and contaminate the first group with supporting voices that emphasize weaker evidence, use poor logic, name-drop socially questionable sources, and go out of their way to sound ridiculous.

Bingo

Re: Snowden leak: Cavium networking hardware may contain NSA backdoor

#627
post #285

More interestingly, Cavium (now Marvell) also designed and manufactured the HSMs which are used by the top cloud providers (such as AWS, GCP, possibly Azure too), to hold the most critical private keys: https://www.prnewswire.com/news-releases/caviums-liquidsecur...

…which is really weird. At least Google and Microsoft are quite outspoken about their in-house secure element technology. If nothing else, at Google/Amazon scale, I’d be concerned about a third-party HSM losing data.

In-house stuff is for security.

HSMs are mainly for compliance, where a customer needs to check a regulatory box, because some rules says you must use a HSM. The more standard it is, the easier it is to demonstrate to the auditor that you've checked the box.

Post reply on HN