Live data from Hacker News

Juniper breach mystery starts to clear with new details on hackers and U.S. role

bloomberg.com

121–130 of 180 posts

Re: Juniper breach mystery starts to clear with new details on hackers and U.S. role

#122
Something I still fail to grasp entirely: according to the Twitter feed discussed here previously [1] the NSA just wanted Dual EC "in there", even, if nobody would use it, but they could use it. (They would even allow the choice of alternative values for P and Q.) Was this relying on negotiating encryption methods while establishing connections? Or did this imply yet another attack?

[1] https://news.ycombinator.com/item?id=28404219

Re: Juniper breach mystery starts to clear with new details on hackers and U.S. role

#123

Earlier quoted context omitted.

Open- and FreeBSD deserve more usage

Well, JunOS is FreeBSD -- the magic is in their proprietary hardware. I'm not aware of open/whitebox solutions that can compete

There’s nothing special with the asics. Juniper makes it’s own Core and Edge routing chips but Arista competes successfully using Broadcom silicon.

Re: Juniper breach mystery starts to clear with new details on hackers and U.S. role

#124
post #109

It's too bad Soekris is gone. For home and small-corp networks they made an awesome router and you could put your favorite Linux on there. Trustable devices are hard to find. Also, if anyone knows of a Soekris like alternative I'm all ears, what to do if my 6501 and my spare 6501 die. Edit: this http://www.soekris.com/products/net6501-1.html

https://protectli.com/

Re: Juniper breach mystery starts to clear with new details on hackers and U.S. role

#126
post #109

It's too bad Soekris is gone. For home and small-corp networks they made an awesome router and you could put your favorite Linux on there. Trustable devices are hard to find. Also, if anyone knows of a Soekris like alternative I'm all ears, what to do if my 6501 and my spare 6501 die. Edit: this http://www.soekris.com/products/net6501-1.html

IIRC Soekris basically decided they couldn't make any money. Is PC Engines acceptable as an alternative? E.g. https://www.pcengines.ch/apu4d4.htm It does have limitations, e.g. only 1 GHz clock speed. The bigger problem for all manufacturers is the chip shortage. E.g. most of PC Engines stuff is "expected ~ 2022". But there may be some stock at their distributors. https://www.pcengines.ch/newshop.php?c=4 Edit: if you…

Thanks!

Re: Juniper breach mystery starts to clear with new details on hackers and U.S. role

#127
post #109

It's too bad Soekris is gone. For home and small-corp networks they made an awesome router and you could put your favorite Linux on there. Trustable devices are hard to find. Also, if anyone knows of a Soekris like alternative I'm all ears, what to do if my 6501 and my spare 6501 die. Edit: this http://www.soekris.com/products/net6501-1.html

https://protectli.com/

Wow, these look awesome, great specs and options.

Re: Juniper breach mystery starts to clear with new details on hackers and U.S. role

#128
post #44

> Members of a hacking group linked to the Chinese government called APT 5 hijacked the NSA algorithm Just wanted to acknowledge how brilliant that is. They could have made any other code change, but it was genius using NSA's own backdoor. NSA advocated for that backdoor to be included in the standards. The US government then would be embarrassed and would want to cover up any issues related to it, including the fact…

Just wanted to acknowledge how brilliant that is. They could have made any other code change, but it was genius using NSA's own backdoor.

Steal the other guy's stuff is no longer brilliant, it's not even surprising. It shouldn't have been surprising to "brilliant" people advocating back doors back in the day.

Re: Juniper breach mystery starts to clear with new details on hackers and U.S. role

#130
post #3

This is ground breaking. The NSA made Juniper use a backdoored algorithm, and a foreign adversary hacked into Juniper and changed the backdoor key (essentially). That's surreal.

Not surreal at all. It's exactly what everyone in the cryptography communuty said would happen if people listened to the government and added backdoors for the "good guys". Hope this sort of thing keeps happening. I want more concrete examples to cite when people defend this stupidity. I want the governments of the world to be too embarrassed to talk about cryptography ever again, least of all demand backdoors into p…

Everyone think the key will be leaked / mis-used. Nobody think it would be changed by other group without noticing.
Post reply on HN