Live data from Hacker News

Juniper breach mystery starts to clear with new details on hackers and U.S. role

bloomberg.com

11–20 of 180 posts

Re: Juniper breach mystery starts to clear with new details on hackers and U.S. role

#11
post #6

This is a great example of why more operators should adopt white box solutions.

It would be interesting to see a refreshed view of what products white-box is able to replace. I recall that Juniper and Cisco were hard to replace for some products because the performance edge was in proprietary ASICs that aren't available to white box builders.

I suspect that CPU improvements and things like user-space networking (DPDK and friends) might have closed the gap some, but I haven't seen any recent analysis.

Re: Juniper breach mystery starts to clear with new details on hackers and U.S. role

#12
post #10

We are playing with a slippery slope! A backdoor is a backdoor. Honestly it is getting to the point where open source is the only way to go - imo. I'd like to be able to perform SAST scans and code review on all software that protects my enclaves.

Maybe I’m just jaded but isnt this the bottom of the slippery slope? The backdoored algorithm from a state actor was the slippery slope.

Starting to think “slippery slope” worries are unfalsifiable, because there is no standard for admitting that the precedent already occurred and the worst scenario already happened.

Oh yeah, and unfalsifiable things are illegitimate to me

Re: Juniper breach mystery starts to clear with new details on hackers and U.S. role

#13
post #10

We are playing with a slippery slope! A backdoor is a backdoor. Honestly it is getting to the point where open source is the only way to go - imo. I'd like to be able to perform SAST scans and code review on all software that protects my enclaves.

Maybe I’m just jaded but isnt this the bottom of the slippery slope? The backdoored algorithm from a state actor was the slippery slope. Starting to think “slippery slope” worries are unfalsifiable, because there is no standard for admitting that the precedent already occurred and the worst scenario already happened. Oh yeah, and unfalsifiable things are illegitimate to me

Lol. Yes you are right. I was directly referencing the idea of purposful backdoors becoming the norm.

Re: Juniper breach mystery starts to clear with new details on hackers and U.S. role

#14
post #10

We are playing with a slippery slope! A backdoor is a backdoor. Honestly it is getting to the point where open source is the only way to go - imo. I'd like to be able to perform SAST scans and code review on all software that protects my enclaves.

Most open source crypto code just does what NIST and DJB say to do. There's no magic imparted by it being FOSS.

Re: Juniper breach mystery starts to clear with new details on hackers and U.S. role

#15
The intentional weakening of ECC has been an open secret for decades, and it's suspicious that this wasn't known by Juniper.

I wonder if they were coerced into including it?

https://www.schneier.com/blog/archives/2007/11/the_strange_s...

Re: Juniper breach mystery starts to clear with new details on hackers and U.S. role

#16
post #3

This is ground breaking. The NSA made Juniper use a backdoored algorithm, and a foreign adversary hacked into Juniper and changed the backdoor key (essentially). That's surreal.

That's what security researchers and cryptographers had been warning about all along. Security for thee but not for me doesn't work.

Re: Juniper breach mystery starts to clear with new details on hackers and U.S. role

#17
post #3

This is ground breaking. The NSA made Juniper use a backdoored algorithm, and a foreign adversary hacked into Juniper and changed the backdoor key (essentially). That's surreal.

What if an insider helped the foreign adversary gain access?

Re: Juniper breach mystery starts to clear with new details on hackers and U.S. role

#18
post #3

This is ground breaking. The NSA made Juniper use a backdoored algorithm, and a foreign adversary hacked into Juniper and changed the backdoor key (essentially). That's surreal.

> The NSA made Juniper use a backdoored algorithm

It's very important to clarify that the NSA didn't make them use it. The DoD required it as terms for future contracts. Juniper grabbed the money in knowing exchange for putting their customers at risk.

Why does that distinction matter? It dramatically increases Juniper's culpability in the scheme. If the DoD had actually forced them to use it, that dramatically reduces Juniper's culpability.

Re: Juniper breach mystery starts to clear with new details on hackers and U.S. role

#20
post #3

This is ground breaking. The NSA made Juniper use a backdoored algorithm, and a foreign adversary hacked into Juniper and changed the backdoor key (essentially). That's surreal.

> The NSA made Juniper use a backdoored algorithm It's very important to clarify that the NSA didn't make them use it. The DoD required it as terms for future contracts. Juniper grabbed the money in knowing exchange for putting their customers at risk. Why does that distinction matter? It dramatically increases Juniper's culpability in the scheme. If the DoD had actually forced them to use it, that dramatically reduc…

This is exactly how they "make" a company do something. Look at what happened to the Qwest (IIRC?) CEO to see what happens if you refuse these contracts.
Post reply on HN