Live data from Hacker News

Juniper breach mystery starts to clear with new details on hackers and U.S. role

bloomberg.com

101–110 of 180 posts

Re: Juniper breach mystery starts to clear with new details on hackers and U.S. role

#101
post #5
post #3

This is ground breaking. The NSA made Juniper use a backdoored algorithm, and a foreign adversary hacked into Juniper and changed the backdoor key (essentially). That's surreal.

This smacks way more of "well, what did you expect would happen?" than surrealism. If you introduce a vulnerability, it is nothing but hubris to think that you'll be the only one to leverage the vulnerability.

It's decades of antivirus style mindsets (we'll just clean up after), mixed with formerly being in law "enforcement" (we can't do anything until AFTER the law is broken), mixed with decades of "security by obscurity" and paranoid "hide and seek" culture, mixed with 9/11 vengeance, plus American exceptionalism.

With a smack of ham to it. I call it hot ham water.

Re: Juniper breach mystery starts to clear with new details on hackers and U.S. role

#102
post #7

How many more back-doors like that are out there that are not in public domain yet? And can we trust standard committees who, funded by public, put back doors in encryption and weaken security of public services?

I'm actually thinking we have these kinds of backdoors in all products that may impact national security. Think it this way: What's the best way for NSA to conveniently access any product without pulling any string because doing so may alert the perpetrator? This is the only way that it can do it quietly. Of course, theoretically they could hire massively numbers of researchers and programmers but I don't really think it's gonna enough.

Re: Juniper breach mystery starts to clear with new details on hackers and U.S. role

#103
post #3

This is ground breaking. The NSA made Juniper use a backdoored algorithm, and a foreign adversary hacked into Juniper and changed the backdoor key (essentially). That's surreal.

It's not groundbreaking: it happened again and again.

How do you know it isn't still happening?

Re: Juniper breach mystery starts to clear with new details on hackers and U.S. role

#104

Earlier quoted context omitted.

I'm surprised we haven't seen an article explaining that the chip shortage is due to so many hidden chips being secretly placed on mobos used by the largest vendors.

Why is that story so far fetched exactly?

If you are referring to Bloomberg's bombshell story about rogue chips installed on motherboards in China during assembly at the factory that then have compromised Apple and Amazon (referenced here: https://www.aei.org/technology-and-innovation/bloombergs-bom...) than the far-fetched element is that it has been three years since the story came out and not a single element of physical evidence have been presented, when one would simply need a microscope to find them in devices. This after multiple major news organizations spent years trying to follow-up on the story and found no evidence whatsoever to back it up.

It was a game of telephone gone horribly wrong, and Bloomberg's reputation is shot since they have refused to retract it.

Re: Juniper breach mystery starts to clear with new details on hackers and U.S. role

#105
post #72

For its first 50 years or so NSA had a dual mission: protect the US from spying while spying on others. But these last 20 years they've undermined that first mission. They've now attacked and weakened American technology so many times that you'd be crazy to trust anything the NSA offers to make you more secure. It doesn't help when they lose control of their own hacking tools igniting a major expansion in ransomware.…

> you'd be crazy to trust anything the NSA offers to make you more secure You'd also be crazy to trust anything made by American gear vendors. This is not the only instance of this, just one of the ones for which FVEY got caught. Is non-US gear also compromised? Yeah, probably. But the PLA and the GRU can't physically confine you to an 8x8 steel cage on trumped-up charges predicated on the data they exfil from your n…

Your best bet is to use things developed entirely in the open. Even if that compromises performance.

Re: Juniper breach mystery starts to clear with new details on hackers and U.S. role

#106
post #92
post #72

Earlier quoted context omitted.

> you'd be crazy to trust anything the NSA offers to make you more secure You'd also be crazy to trust anything made by American gear vendors. This is not the only instance of this, just one of the ones for which FVEY got caught. Is non-US gear also compromised? Yeah, probably. But the PLA and the GRU can't physically confine you to an 8x8 steel cage on trumped-up charges predicated on the data they exfil from your n…

Would you be safe by running multiple layers around your network? Each layer from a different vendor?

It depends on your threat level.

Re: Juniper breach mystery starts to clear with new details on hackers and U.S. role

#107
post #44

> Members of a hacking group linked to the Chinese government called APT 5 hijacked the NSA algorithm Just wanted to acknowledge how brilliant that is. They could have made any other code change, but it was genius using NSA's own backdoor. NSA advocated for that backdoor to be included in the standards. The US government then would be embarrassed and would want to cover up any issues related to it, including the fact…

When an Agency with the purpose of ensuring the Security of the Nation does the exact opposite... makes you wonder why they even exist.

"What would you say you do here?"

Re: Juniper breach mystery starts to clear with new details on hackers and U.S. role

#108
post #99
post #14

Earlier quoted context omitted.

Most open source crypto code just does what NIST and DJB say to do. There's no magic imparted by it being FOSS.

NIST or DJB. It's safer to ignore NIST and do what DJB says.

Makes NIST's responses towards DJB in the PQ crypto process have been ... interesting.

https://groups.google.com/a/list.nist.gov/g/pqc-forum/c/3mVe...

Re: Juniper breach mystery starts to clear with new details on hackers and U.S. role

#109
It's too bad Soekris is gone. For home and small-corp networks they made an awesome router and you could put your favorite Linux on there. Trustable devices are hard to find.

Also, if anyone knows of a Soekris like alternative I'm all ears, what to do if my 6501 and my spare 6501 die.

Edit: this http://www.soekris.com/products/net6501-1.html

Re: Juniper breach mystery starts to clear with new details on hackers and U.S. role

#110
post #10

We are playing with a slippery slope! A backdoor is a backdoor. Honestly it is getting to the point where open source is the only way to go - imo. I'd like to be able to perform SAST scans and code review on all software that protects my enclaves.

This was known to be compromised, though. People using it anyway weren't being fooled because they couldn't audit the code. They were forced by federal standards or they'd lose the ability to sell to the government and go out of business.

Your best bet is multiple layers of defense. It may sound ridiculous, but don't use just one VPN/firewall. Make your adversaries compromise multiple vendors. Encrypt several times. That's what the actual DoD does and why the NSA probably doesn't even care. And, of course, the really important information is classified and never hits a publicly reachable network at all, so compromising the supply chain doesn't even help. As a private organization, you probably don't have the option to build an entirely separate network that doesn't touch the Internet and then protect the ingress/egress nodes with your own private military, so I don't know what to tell you there.

Post reply on HN