Live data from Hacker News

Juniper breach mystery starts to clear with new details on hackers and U.S. role

bloomberg.com

131–140 of 180 posts

Re: Juniper breach mystery starts to clear with new details on hackers and U.S. role

#131
post #6

This is a great example of why more operators should adopt white box solutions.

Whitebox solutions can be adopted by corporations that can afford to have dedicated teams to maintain the software stack. For others, it can be quite risky.

Re: Juniper breach mystery starts to clear with new details on hackers and U.S. role

#132
post #6

This is a great example of why more operators should adopt white box solutions.

Whitebox solutions can be adopted by corporations that can afford to have dedicated teams to maintain the software stack. For others, it can be quite risky.

> Whitebox solutions can be adopted by corporations that can afford to have dedicated teams to maintain the software stack.

Pretty much. Unless you have some remarkably top-notch people, this proposal is just security theatre. The chances you'll compromise yourself through an error in a complex area are much higher than the liklihood a sophisticated attacker will breach you.

Re: Juniper breach mystery starts to clear with new details on hackers and U.S. role

#133

For its first 50 years or so NSA had a dual mission: protect the US from spying while spying on others. But these last 20 years they've undermined that first mission. They've now attacked and weakened American technology so many times that you'd be crazy to trust anything the NSA offers to make you more secure. It doesn't help when they lose control of their own hacking tools igniting a major expansion in ransomware.…

You are correct, and the transition point was 9/11. Before that the NSA was doing good work shoring up our digital infrastructure, as well as working with the FBI to go after international crime syndicates. I wish we could get back to that.

> Before that the NSA was doing good work shoring up our digital infrastructure

Yeah, like introducing the Clipper chip!

Re: Juniper breach mystery starts to clear with new details on hackers and U.S. role

#134
post #3

This is ground breaking. The NSA made Juniper use a backdoored algorithm, and a foreign adversary hacked into Juniper and changed the backdoor key (essentially). That's surreal.

> The NSA made Juniper use a backdoored algorithm It's very important to clarify that the NSA didn't make them use it. The DoD required it as terms for future contracts. Juniper grabbed the money in knowing exchange for putting their customers at risk. Why does that distinction matter? It dramatically increases Juniper's culpability in the scheme. If the DoD had actually forced them to use it, that dramatically reduc…

I don't get why this is downvoted. There is a huge difference between, say, a court order or other force-backed request and a requirement in a bidding process.

It doesn't absolve the NSA of any guilt here either, but this is not a helpless Juniper giving in due to full weight and power of the government.

Re: Juniper breach mystery starts to clear with new details on hackers and U.S. role

#135
post #44

> Members of a hacking group linked to the Chinese government called APT 5 hijacked the NSA algorithm Just wanted to acknowledge how brilliant that is. They could have made any other code change, but it was genius using NSA's own backdoor. NSA advocated for that backdoor to be included in the standards. The US government then would be embarrassed and would want to cover up any issues related to it, including the fact…

When an Agency with the purpose of ensuring the Security of the Nation does the exact opposite... makes you wonder why they even exist.

Don’t worry though, I’m sure Congress is on the case and will put things back on track! /s

Re: Juniper breach mystery starts to clear with new details on hackers and U.S. role

#136
post #72

For its first 50 years or so NSA had a dual mission: protect the US from spying while spying on others. But these last 20 years they've undermined that first mission. They've now attacked and weakened American technology so many times that you'd be crazy to trust anything the NSA offers to make you more secure. It doesn't help when they lose control of their own hacking tools igniting a major expansion in ransomware.…

> you'd be crazy to trust anything the NSA offers to make you more secure You'd also be crazy to trust anything made by American gear vendors. This is not the only instance of this, just one of the ones for which FVEY got caught. Is non-US gear also compromised? Yeah, probably. But the PLA and the GRU can't physically confine you to an 8x8 steel cage on trumped-up charges predicated on the data they exfil from your n…

>But the PLA and the GRU can't physically confine you to an 8x8 steel cage on trumped-up charges predicated on the data they exfil from your network.

Actually they can, and with less legal recourse for you than in the US. It just depends on where in the world you happen to be when they decide they want you.

Re: Juniper breach mystery starts to clear with new details on hackers and U.S. role

#137

I don't understand it. If the APT-5 can do code change, they can have their own backdoored PRNG. They don't have to reuse the NSA backdoor.

By leveraging an existing backdoor they are reducing the chances of their own activity being detected. Attempting to introduce a net new backdoor may have led to them generating additional indicators of compromise and risked being detected sooner.

Re: Juniper breach mystery starts to clear with new details on hackers and U.S. role

#138

Earlier quoted context omitted.

> The NSA made Juniper use a backdoored algorithm It's very important to clarify that the NSA didn't make them use it. The DoD required it as terms for future contracts. Juniper grabbed the money in knowing exchange for putting their customers at risk. Why does that distinction matter? It dramatically increases Juniper's culpability in the scheme. If the DoD had actually forced them to use it, that dramatically reduc…

Which is why Room 641A is filled with Juniper gear. https://en.wikipedia.org/wiki/Room_641A

That doesn't make any sense, the operators of Room 641A don't need to backdoor their own gear.

Re: Juniper breach mystery starts to clear with new details on hackers and U.S. role

#139
post #109

It's too bad Soekris is gone. For home and small-corp networks they made an awesome router and you could put your favorite Linux on there. Trustable devices are hard to find. Also, if anyone knows of a Soekris like alternative I'm all ears, what to do if my 6501 and my spare 6501 die. Edit: this http://www.soekris.com/products/net6501-1.html

PCEngines[0]?

[0] https://pcengines.ch/apu2.htm

Re: Juniper breach mystery starts to clear with new details on hackers and U.S. role

#140
post #23
post #3

This is ground breaking. The NSA made Juniper use a backdoored algorithm, and a foreign adversary hacked into Juniper and changed the backdoor key (essentially). That's surreal.

Is there a list of exactly what equipment (model numbers) was breached?

Yes. The model number is J-U-N-I-P-E-R.

You can argue that is was a software problem, not a hardware problem. This is wrong. It was a human problem. The humans involved span the software and hardware and more across all models.

Post reply on HN