Live data from Hacker News

Juniper breach mystery starts to clear with new details on hackers and U.S. role

bloomberg.com

111–120 of 180 posts

Re: Juniper breach mystery starts to clear with new details on hackers and U.S. role

#111
I am cautious on the purported facts of anything reported when it comes out of "Bloomberg News investigation" that "has filled in significant new details."

In my opinion, they jump to conclusion on insufficient circumstantial evidence. I have not forgotten the SuperMicro debacle.

In this article, they repeat the some jumping and aggrandizing on multiple fronts.

Re: Juniper breach mystery starts to clear with new details on hackers and U.S. role

#112

Earlier quoted context omitted.

Why is that story so far fetched exactly?

If you are referring to Bloomberg's bombshell story about rogue chips installed on motherboards in China during assembly at the factory that then have compromised Apple and Amazon (referenced here: https://www.aei.org/technology-and-innovation/bloombergs-bom... ) than the far-fetched element is that it has been three years since the story came out and not a single element of physical evidence have been presented, whe…

[deleted]

Re: Juniper breach mystery starts to clear with new details on hackers and U.S. role

#113
post #3

This is ground breaking. The NSA made Juniper use a backdoored algorithm, and a foreign adversary hacked into Juniper and changed the backdoor key (essentially). That's surreal.

> The NSA made Juniper use a backdoored algorithm It's very important to clarify that the NSA didn't make them use it. The DoD required it as terms for future contracts. Juniper grabbed the money in knowing exchange for putting their customers at risk. Why does that distinction matter? It dramatically increases Juniper's culpability in the scheme. If the DoD had actually forced them to use it, that dramatically reduc…

Which is why Room 641A is filled with Juniper gear.

https://en.wikipedia.org/wiki/Room_641A

Re: Juniper breach mystery starts to clear with new details on hackers and U.S. role

#114

Earlier quoted context omitted.

Open- and FreeBSD deserve more usage

Well, JunOS is FreeBSD -- the magic is in their proprietary hardware. I'm not aware of open/whitebox solutions that can compete

Which platform? Most of their hardware uses commodity ASIC/npu which really isn't magic, lots of great white label choices around.

Re: Juniper breach mystery starts to clear with new details on hackers and U.S. role

#115

Earlier quoted context omitted.

> The NSA made Juniper use a backdoored algorithm It's very important to clarify that the NSA didn't make them use it. The DoD required it as terms for future contracts. Juniper grabbed the money in knowing exchange for putting their customers at risk. Why does that distinction matter? It dramatically increases Juniper's culpability in the scheme. If the DoD had actually forced them to use it, that dramatically reduc…

This is exactly how they "make" a company do something. Look at what happened to the Qwest (IIRC?) CEO to see what happens if you refuse these contracts.

I hate this meme. It's false.

Nacchio simply tried to use it as an excuse. He was just throwing shit against the wall and hoping that some of it stuck. Here's his claim: he was not in a rightful state of mind when he sold his shares because of problems with his son, and the imminent announcement of a number of government contracts.

Yeah sure, I know exactly what he means. Whenever I'm not in a "rightful state of mind" the way I cope with it is to dump company stock that I'm restricted from selling. /s

Nacchio was nothing but a greedy scumbag, and he went to Federal prison because of it.

https://en.wikipedia.org/wiki/Joseph_Nacchio

Re: Juniper breach mystery starts to clear with new details on hackers and U.S. role

#116

I am cautious on the purported facts of anything reported when it comes out of "Bloomberg News investigation" that "has filled in significant new details." In my opinion, they jump to conclusion on insufficient circumstantial evidence. I have not forgotten the SuperMicro debacle. In this article, they repeat the some jumping and aggrandizing on multiple fronts.

I checked out of curiosity and the SuperMicro article was written by the same author, Jordan Robertson. Make of that what you will.

https://www.bloomberg.com/news/features/2018-10-04/the-big-h...

Re: Juniper breach mystery starts to clear with new details on hackers and U.S. role

#117
post #109

It's too bad Soekris is gone. For home and small-corp networks they made an awesome router and you could put your favorite Linux on there. Trustable devices are hard to find. Also, if anyone knows of a Soekris like alternative I'm all ears, what to do if my 6501 and my spare 6501 die. Edit: this http://www.soekris.com/products/net6501-1.html

IIRC Soekris basically decided they couldn't make any money.

Is PC Engines acceptable as an alternative? E.g. https://www.pcengines.ch/apu4d4.htm

It does have limitations, e.g. only 1 GHz clock speed.

The bigger problem for all manufacturers is the chip shortage. E.g. most of PC Engines stuff is "expected ~ 2022". But there may be some stock at their distributors. https://www.pcengines.ch/newshop.php?c=4

Edit: if you dig deeper you may also find hardware you didn't expect. E.g. at some point OpenBSD was able to run on some Ubiquiti hardware. I don't know if Ubiquiti still make products that can run OpenBSD. https://www.openbsd.org/octeon.html

Re: Juniper breach mystery starts to clear with new details on hackers and U.S. role

#118
post #99
post #14

Earlier quoted context omitted.

Most open source crypto code just does what NIST and DJB say to do. There's no magic imparted by it being FOSS.

NIST or DJB. It's safer to ignore NIST and do what DJB says.

Well that's what most open source does today. GitHub posted a blog post four days ago that the majority of SSH clients have moved away from aes to chacha. https://github.blog/2021-09-01-improving-git-protocol-securi... I wouldn't be surprised if the majority of https traffic uses x25519 these days instead of rsa or ℘256. djb is an influential guy.

Re: Juniper breach mystery starts to clear with new details on hackers and U.S. role

#119
post #95

Earlier quoted context omitted.

Actually I think P4 programmable switch ASICs such as Barefoot are going to become more prevalent over time and hence features will be available in software.

hasn't P4 been kind of dead in the water for the last couple of years.

P4 programmability is available in Cisco Silicon One so wouldn’t call P4 dead in the water. Cisco Silicon One is meant to go head to head against Broadcom.

https://www.cisco.com/c/en/us/solutions/collateral/silicon-o...

In other merchant silicon, while not P4, Broadcom has offered their own proprietary programmability in Trident 3/4.

I think adoption has been slower more due to lack of relevant domain expertise in software as well as relative inability of pretty much anyone to properly model the impact of routing features on a production network than anything else.

P4 is being widely adopted at the NIC level.

Re: Juniper breach mystery starts to clear with new details on hackers and U.S. role

#120
post #73
post #40

Earlier quoted context omitted.

No, you can't trust NIST on security. They've certified algorithms they must have known were deliberately weakened in every generation: DES in the 1970s, the Clipper chip in the 80s, "export-grade" RSA in the 90s, and broken RNGs in the 2000s. The deliberate weakening generally comes from the NSA, but NIST is required to work with them on security standards. A number of reputable security researchers claim that NIST'…

I think this is a little unfair to NIST. Some parts aren't entirely factual. For example while DES was specified at 56 bits if we discount parity bits, I'm not sure how much choice they had in this - I suspect NSA/US gov more widely here. NSA, which is distinct from NIST but obviously works with them, requested changes to the DES S-Boxes during design that resulted in better protection from differential cryptanalysis…

> "Intentional use of escrow keys can provide for back up functionality. The relationship between P and Q is used as an escrow key and stored by for a security domain. The administrator logs the output of the generator to reconstruct the random number with the escrow key." [1]

We were just using it wrong, it's a backup tool, not an encryption standard. ;-)

[1] US2007189527, abstract: https://news.ycombinator.com/reply?id=28427331&goto=item%3Fi...

Post reply on HN