Live data from Hacker News

Juniper breach mystery starts to clear with new details on hackers and U.S. role

bloomberg.com

151–160 of 180 posts

Re: Juniper breach mystery starts to clear with new details on hackers and U.S. role

#151
post #44

> Members of a hacking group linked to the Chinese government called APT 5 hijacked the NSA algorithm Just wanted to acknowledge how brilliant that is. They could have made any other code change, but it was genius using NSA's own backdoor. NSA advocated for that backdoor to be included in the standards. The US government then would be embarrassed and would want to cover up any issues related to it, including the fact…

> Just wanted to acknowledge how brilliant that is. They could have made any other code change, but it was genius using NSA's own backdoor.

It is much more plausible that US companies didn't want to name and shame their biggest customer than the Chinese reverse engineering a cryptographic backdoor. This could have been supported by the general NSA/GCHQ efforts to ensure their activies are mis-attributed.

The "it was China" determination was made by Mandiant, a company that receives over half its revenue from the US government (per the 2014 FireEye M&A call).

Heck, Microsoft (Longhorn), SecureWorks (Platinum Colony), and Google (GOSSIPGIRL) are the only US companies that have even publicly assigned names to track US linked APT groups.

Re: Juniper breach mystery starts to clear with new details on hackers and U.S. role

#152
post #73
post #40

Earlier quoted context omitted.

No, you can't trust NIST on security. They've certified algorithms they must have known were deliberately weakened in every generation: DES in the 1970s, the Clipper chip in the 80s, "export-grade" RSA in the 90s, and broken RNGs in the 2000s. The deliberate weakening generally comes from the NSA, but NIST is required to work with them on security standards. A number of reputable security researchers claim that NIST'…

I think this is a little unfair to NIST. Some parts aren't entirely factual. For example while DES was specified at 56 bits if we discount parity bits, I'm not sure how much choice they had in this - I suspect NSA/US gov more widely here. NSA, which is distinct from NIST but obviously works with them, requested changes to the DES S-Boxes during design that resulted in better protection from differential cryptanalysis…

> [...] I'm not sure how much choice they had in this - I suspect NSA/US gov more widely here. [...]

Note that when parent says "you can't trust NIST" and you counter with something along the lines of "that's unfair... NIST acts untrustworthy/knowingly recommends subpar options because of NSA", it doesn't really counter what is being said.

If NIST decisions are based mostly on "whatever the NSA tells them to do", rather than the actual technical merits of the things they recommend, then... yes, they are generally not worthy of trust (blind or otherwise), because you'll always have to double-check their statements against other sources (e.g. your own knowledge, expert cryptographers, etc.).

Fool me once, shame on you; fool me twice, shame on me.

That's the problem of being untrustworthy once in a while... it's easier to lose your reputation than to regain it.

As it is... if you use anything recommended by NIST without first checking with the actual trustworthy community of researchers, you're asking for it.

TL;DR: Trying to justify why the NIST is seen as untrustworthy (or acts as such) does not change the fact that it is seen as untrustworthy by many people (and, as far as I can tell, fairly so).

Re: Juniper breach mystery starts to clear with new details on hackers and U.S. role

#153
FTA: "The request prompted concern among some Juniper engineers, but ultimately the code was added to appease a large customer, the employees said."

So basically, it means that "appeasing a customer" is a very easy and cheap way to control engineers... From there on, realize that there's no security at all for those who are not able to make their own.

Now let's talk about ethics in the engineer's training...

Re: Juniper breach mystery starts to clear with new details on hackers and U.S. role

#154
post #151
post #44

> Members of a hacking group linked to the Chinese government called APT 5 hijacked the NSA algorithm Just wanted to acknowledge how brilliant that is. They could have made any other code change, but it was genius using NSA's own backdoor. NSA advocated for that backdoor to be included in the standards. The US government then would be embarrassed and would want to cover up any issues related to it, including the fact…

> Just wanted to acknowledge how brilliant that is. They could have made any other code change, but it was genius using NSA's own backdoor. It is much more plausible that US companies didn't want to name and shame their biggest customer than the Chinese reverse engineering a cryptographic backdoor. This could have been supported by the general NSA/GCHQ efforts to ensure their activies are mis-attributed. The "it was…

> Heck, Microsoft (Longhorn), SecureWorks (Platinum Colony), and Google (GOSSIPGIRL) are the only US companies that have even publicly assigned names to track US linked APT groups.

I didn't understand this statement, but it's intrigued me. What are the names for and how do they lead to tracking US-linked APT (advanced, persistent threat a.k.a state sponsored) groups and who's doing the tracking?

Re: Juniper breach mystery starts to clear with new details on hackers and U.S. role

#155
post #108
post #99

Earlier quoted context omitted.

NIST or DJB. It's safer to ignore NIST and do what DJB says.

Makes NIST's responses towards DJB in the PQ crypto process have been ... interesting. https://groups.google.com/a/list.nist.gov/g/pqc-forum/c/3mVe...

It's even more interesting that DJB did not care to answer

Re: Juniper breach mystery starts to clear with new details on hackers and U.S. role

#156

Earlier quoted context omitted.

Why is that story so far fetched exactly?

If you are referring to Bloomberg's bombshell story about rogue chips installed on motherboards in China during assembly at the factory that then have compromised Apple and Amazon (referenced here: https://www.aei.org/technology-and-innovation/bloombergs-bom... ) than the far-fetched element is that it has been three years since the story came out and not a single element of physical evidence have been presented, whe…

Bloomberg continues to build on this theory (same reporter AFAIK) even as recently as this year https://www.bloomberg.com/features/2021-supermicro/

Re: Juniper breach mystery starts to clear with new details on hackers and U.S. role

#158

The intentional weakening of ECC has been an open secret for decades, and it's suspicious that this wasn't known by Juniper. I wonder if they were coerced into including it? https://www.schneier.com/blog/archives/2007/11/the_strange_s...

This has nothing to do with "weakening of ECC". Dual_EC_DRBG is an RNG that happens to use Elliptic Curves but its problems have nothing to do with that, they have to do with the design of the RNG itself. And those problems don't say anything about the strength of ECC used for encryption and digital signatures.

Re: Juniper breach mystery starts to clear with new details on hackers and U.S. role

#159
post #105
post #72

Earlier quoted context omitted.

> you'd be crazy to trust anything the NSA offers to make you more secure You'd also be crazy to trust anything made by American gear vendors. This is not the only instance of this, just one of the ones for which FVEY got caught. Is non-US gear also compromised? Yeah, probably. But the PLA and the GRU can't physically confine you to an 8x8 steel cage on trumped-up charges predicated on the data they exfil from your n…

Your best bet is to use things developed entirely in the open. Even if that compromises performance.

That doesn't help if you're trying to be safe from a powerful world government - one with the resources and will to infiltrate an open project for its own ends. It's far less likely that there are US backdoors in Huawei routers (which surely contain Chinese backdoors!) than in any mostly american open-source software you pick.

Re: Juniper breach mystery starts to clear with new details on hackers and U.S. role

#160

Earlier quoted context omitted.

Probably pretty chill internally. "The thing we knew would happen and that every expert said would happen happened."

I think you may be surprised, in the NSA they refer to some exploits as NOBUS (nobody but us) where they earnestly believed that only they had the knowledge and capability to find and carry out certain exploits. https://en.wikipedia.org/wiki/NOBUS

It seems silly now, especially as the civilian bar for these types of exploits continually lowers, but it's not unreasonable for them to have believed something like this decades ago, especially before widespread computer usage.
Post reply on HN