Snowden leak: Cavium networking hardware may contain NSA backdoor
141–150 of 628 posts
Re: Snowden leak: Cavium networking hardware may contain NSA backdoor
#142Earlier quoted context omitted.
Huawei stuff is proven to be compromised, just not by NSA, instead by China.
Where is the proof?
Re: Snowden leak: Cavium networking hardware may contain NSA backdoor
#143Earlier quoted context omitted.
I'd be surprised if you get anything more than generic statements about how they take security very seriously and they are open to suggestions, but avoid addressing the mentioned concerns directly (and this applies to all cloud providers out there, not just AWS). I'm sure a few others here would like to see their response as well.
We've had other issues with our CloudHSM instance, especially with the PKCS1.5 deprecation on January 1. And their support has been pretty dismal. Not expecting much from them at this point.
Re: Snowden leak: Cavium networking hardware may contain NSA backdoor
#144More interestingly, Cavium (now Marvell) also designed and manufactured the HSMs which are used by the top cloud providers (such as AWS, GCP, possibly Azure too), to hold the most critical private keys: https://www.prnewswire.com/news-releases/caviums-liquidsecur...
Is there anyone here who actually thought cloud provider HSMs were secure against the provider itself or whatever nation state(s) have jurisdiction over it? It would never occur to me to even suspect that. I assume that anything I do in the cloud is absolutely transparent to the cloud provider unless it's running homomorphic encryption, which is still too slow and limited to do much that is useful. I would trust them…
Even when you are a nation state, you still have to worry about other nation states.
Re: Snowden leak: Cavium networking hardware may contain NSA backdoor
#145Earlier quoted context omitted.
Is there anyone here who actually thought cloud provider HSMs were secure against the provider itself or whatever nation state(s) have jurisdiction over it? It would never occur to me to even suspect that. I assume that anything I do in the cloud is absolutely transparent to the cloud provider unless it's running homomorphic encryption, which is still too slow and limited to do much that is useful. I would trust them…
Lots of people believe that. They believe truthfully you can get to the level of AWS, MS, Google, Facebook or Apple whilst standing up to the nations that host those companies. I've walked into government employees in the hallways of tiny ISPs, I see no reason to believe at all that larger companies are any different except for when easier backdoors have been installed.
Re: Snowden leak: Cavium networking hardware may contain NSA backdoor
#146The tweet seems to imply that the entire Ubiquiti Networks line of network hardware could be compromised. That's a shame; I was thinking of installing some in my house. I'm sure that Ubiquiti's customers will not be happy if they find out that the US Govt can access their private data.
If you're not under the threat cone of nation state surveillance (like trying to exfiltrate the radar-asborbing paint formula on the F35) then I wouldn't be too concerned. "That's not the point! It's about privacy!" Sure. I'll choose it ignore the fact that our civilization is somehow still functioning in a post-nuclear world.
The average reader may be surprised by how far this cone can extend in some circumstances.
It has been established that the NSA conducts industrial espionage [0], under the cover of national security [1]. To what degree the term "national security" narrows down the scope of any surveillance measures is likely unfamiliar to the laymen, but an NSA representative gave a short description on the agencies views to that regard in 2013:
"The intelligence community's efforts to understand economic systems and policies, and monitor anomalous economic activities, are critical to providing policy makers with the information they need to make informed decisions that are in the best interest of our national security." [1]
While it affirms that it does not steal trade secrets, the NSA reserves the right to pass on critical information about economic developments towards policy makers, who then can use this knowledge in their decision making.
Notable examples of industrial espionage conducted by the NSA consisted of spying on EU antitrust regulators investigating Google for antitrust violations [1], alleged espionage of business conducted by brazilian oil giant Petrobas [2], international credit card transactions [3], SWIFT [4], and the infamous allegations of espionage against european defense company EADS [5].
It's noteworthy that this short list only comprises cases that got attention of the media, the actual list of targets in europe was much higher, about 2000 companies in europe, many of them defense contractors.[5]
So, to summarize, it may be much easier to fall into this cone, than one would assume. The agency is also at odds with it's own claims as this this excerpt from a Guardian article [2] clearly shows:
"The department does not engage in economic espionage in any domain, including cyber," the agency said in an emailed response to a Washington Post story on the subject last month. [...] "We collect this information for many important reasons: for one, it could provide the United States and our allies early warning of international financial crises which could negatively impact the global economy. It also could provide insight into other countries' economic policy or behavior which could affect global markets."
But he again denied this amounted to industrial espionage. "What we do not do, as we have said many times, is use our foreign intelligence capabilities to steal the trade secrets of foreign companies on behalf of – or give intelligence we collect to – US companies to enhance their international competitiveness or increase their bottom line." [2]
To me these statements are mutually exclusive: How is providing policy makers with insights from foreign politics and possible industrial espionage (i.e. not necessarily actual technologies, but research objectives of foreign companies) not giving an advantage to domestic companies, if those policy makers act appropriately?
[0]https://theintercept.com/2014/09/05/us-governments-plans-use... [1]https://www.cnet.com/tech/tech-industry/nsa-spied-on-eu-anti... [2]https://www.theguardian.com/world/2013/sep/09/nsa-spying-bra... [3]https://www.spiegel.de/international/world/spiegel-exclusive... [4] https://www.spiegel.de/international/europe/nsa-spying-europ... [5] https://www.theregister.com/2015/04/30/airbus_us_german_inte...
Re: Snowden leak: Cavium networking hardware may contain NSA backdoor
#147Earlier quoted context omitted.
er...what? why do you think any of that has happened? we already saw this happen in public once with Qwest: https://www.eff.org/deeplinks/2007/10/qwest-ceo-nsa-punished...
It’s happened at least three times. They got Yahoo’s CEO to [bypass SOX compliance and] hand over access to 500 million email accounts. Last I heard, she said they convinced her she wasn’t allowed to ask corporate lawyers for guidance. https://www.theguardian.com/technology/2016/oct/04/yahoo-sec... Both she and Yahoo’s shareholders suffered greatly for complying. There’s also Crypto AG, which was a foreign-owned CIA…
To me, anyone purporting to be an official government employee advising you that you cannot speak to an attorney throws up so many red flags, that I just can't imagine it being anything but sinister.
Re: Snowden leak: Cavium networking hardware may contain NSA backdoor
#148How the NSA successfully manage to prevent the Washington Post and friends from discovering and reporting on this malicious backdoor? They've been sitting on these documents for a decade. Are the journalists just that *uncurious* about the deep contents of the documents they hold exclusive access to? Was this some kind of organizational failing?
Re: Snowden leak: Cavium networking hardware may contain NSA backdoor
#149Re: Snowden leak: Cavium networking hardware may contain NSA backdoor
#150The tweet seems to imply that the entire Ubiquiti Networks line of network hardware could be compromised. That's a shame; I was thinking of installing some in my house. I'm sure that Ubiquiti's customers will not be happy if they find out that the US Govt can access their private data.
So, Marvell bought the company that backdoored all my Ubiquiti gear. Since it was never working as advertised, do I contact them or Ubiquiti to get my refund / warranty replacements?