Live data from Hacker News

Juniper breach mystery starts to clear with new details on hackers and U.S. role

bloomberg.com

141–150 of 180 posts

Re: Juniper breach mystery starts to clear with new details on hackers and U.S. role

#141
post #3

This is ground breaking. The NSA made Juniper use a backdoored algorithm, and a foreign adversary hacked into Juniper and changed the backdoor key (essentially). That's surreal.

And if you think they only strong-armed Juniper into doing this, I've got seaside real estate in Nevada to show you. AT LEAST Cisco should be considered compromised as well.

Lakeside property in Nevada is current news.

Re: Juniper breach mystery starts to clear with new details on hackers and U.S. role

#142
post #44

> Members of a hacking group linked to the Chinese government called APT 5 hijacked the NSA algorithm Just wanted to acknowledge how brilliant that is. They could have made any other code change, but it was genius using NSA's own backdoor. NSA advocated for that backdoor to be included in the standards. The US government then would be embarrassed and would want to cover up any issues related to it, including the fact…

Probably pretty chill internally. "The thing we knew would happen and that every expert said would happen happened."

I think you may be surprised, in the NSA they refer to some exploits as NOBUS (nobody but us) where they earnestly believed that only they had the knowledge and capability to find and carry out certain exploits.

https://en.wikipedia.org/wiki/NOBUS

Re: Juniper breach mystery starts to clear with new details on hackers and U.S. role

#145
post #72

Earlier quoted context omitted.

> you'd be crazy to trust anything the NSA offers to make you more secure You'd also be crazy to trust anything made by American gear vendors. This is not the only instance of this, just one of the ones for which FVEY got caught. Is non-US gear also compromised? Yeah, probably. But the PLA and the GRU can't physically confine you to an 8x8 steel cage on trumped-up charges predicated on the data they exfil from your n…

>But the PLA and the GRU can't physically confine you to an 8x8 steel cage on trumped-up charges predicated on the data they exfil from your network. Actually they can, and with less legal recourse for you than in the US. It just depends on where in the world you happen to be when they decide they want you.

Why bother with cages when you can go straight to Novichoking someone's underpants?

Re: Juniper breach mystery starts to clear with new details on hackers and U.S. role

#146

Earlier quoted context omitted.

This is exactly how they "make" a company do something. Look at what happened to the Qwest (IIRC?) CEO to see what happens if you refuse these contracts.

I hate this meme. It's false. Nacchio simply tried to use it as an excuse. He was just throwing shit against the wall and hoping that some of it stuck. Here's his claim: he was not in a rightful state of mind when he sold his shares because of problems with his son, and the imminent announcement of a number of government contracts. Yeah sure, I know exactly what he means. Whenever I'm not in a "rightful state of mind…

Nobody is denying he insider traded, but was the insider trading (or other unlawful activities) of others that did comply go ignored/suppressed or otherwise swept under the rug?

Re: Juniper breach mystery starts to clear with new details on hackers and U.S. role

#147
post #138

Earlier quoted context omitted.

Which is why Room 641A is filled with Juniper gear. https://en.wikipedia.org/wiki/Room_641A

That doesn't make any sense, the operators of Room 641A don't need to backdoor their own gear.

Maybe in exchange for the backdoor they buy a mountain of non-backdoored versions too?

Re: Juniper breach mystery starts to clear with new details on hackers and U.S. role

#148

Something I still fail to grasp entirely: according to the Twitter feed discussed here previously [1] the NSA just wanted Dual EC "in there", even, if nobody would use it, but they could use it. (They would even allow the choice of alternative values for P and Q.) Was this relying on negotiating encryption methods while establishing connections? Or did this imply yet another attack? [1] https://news.ycombinator.com/i…

1. Get the code in there.

2. Tie up a commercial contract with this mode being made the default.

It’s just Apple CSAM all the way down.

Re: Juniper breach mystery starts to clear with new details on hackers and U.S. role

#149
post #148

Something I still fail to grasp entirely: according to the Twitter feed discussed here previously [1] the NSA just wanted Dual EC "in there", even, if nobody would use it, but they could use it. (They would even allow the choice of alternative values for P and Q.) Was this relying on negotiating encryption methods while establishing connections? Or did this imply yet another attack? [1] https://news.ycombinator.com/i…

1. Get the code in there. 2. Tie up a commercial contract with this mode being made the default. It’s just Apple CSAM all the way down.

I would have thought, provided that the aforementioned statements were factual, you had to have some mechanism in place to force a connection to default to this algorithm for this to be useful in a more general way. (Apparently, you want to tap into third party conversations, but are not relying on them actually using this algorithm, rather, just having it implemented.)

Re: Juniper breach mystery starts to clear with new details on hackers and U.S. role

#150

Earlier quoted context omitted.

Why is that story so far fetched exactly?

If you are referring to Bloomberg's bombshell story about rogue chips installed on motherboards in China during assembly at the factory that then have compromised Apple and Amazon (referenced here: https://www.aei.org/technology-and-innovation/bloombergs-bom... ) than the far-fetched element is that it has been three years since the story came out and not a single element of physical evidence have been presented, whe…

>when one would simply need a microscope to find them in devices

This isn't a true statement, if strictly read--there are many techniques to hide undocumented components on boards, and covering all of them requires more than just a pass under a SEM. There's a fun talk that goes over a lot of them here: https://www.youtube.com/watch?v=RqQhWitJ1As

Post reply on HN