Live data from Hacker News

Juniper breach mystery starts to clear with new details on hackers and U.S. role

bloomberg.com

161–170 of 180 posts

Re: Juniper breach mystery starts to clear with new details on hackers and U.S. role

#161
post #138

Earlier quoted context omitted.

Which is why Room 641A is filled with Juniper gear. https://en.wikipedia.org/wiki/Room_641A

That doesn't make any sense, the operators of Room 641A don't need to backdoor their own gear.

There is an interesting aspect of the room 641a story that could turn out to be different in detail:

The Wikipedia article says, as do other accounts, that beam splitters were used to tap into fiber optic lines. That might in fact be how it was done, but I do not think that was necessary.

IIRC, Juniper core routers were (uniquely, at the time?) capable of duplicating traffic on a NIC to another NIC without performance impact on capacity as a whole. This would have made them particularly suitable for mass surveillance that would not show up in network management metrics.

Re: Juniper breach mystery starts to clear with new details on hackers and U.S. role

#162
post #138

Earlier quoted context omitted.

Which is why Room 641A is filled with Juniper gear. https://en.wikipedia.org/wiki/Room_641A

That doesn't make any sense, the operators of Room 641A don't need to backdoor their own gear.

When trying to make sense of why things are the way they are, one very successful technique to use is “follow the money”.

“We want you to backdoor your product for ‘National Security’ and if you do, we’ll buy many millions of dollars worth of your gear.”

What doesn’t make sense about that?

Re: Juniper breach mystery starts to clear with new details on hackers and U.S. role

#163

Earlier quoted context omitted.

Probably pretty chill internally. "The thing we knew would happen and that every expert said would happen happened."

I think you may be surprised, in the NSA they refer to some exploits as NOBUS (nobody but us) where they earnestly believed that only they had the knowledge and capability to find and carry out certain exploits. https://en.wikipedia.org/wiki/NOBUS

The NSA is staffed by non-target candidates that would never get a meeting in Silicon Valley, largely from DC area universities.

Although there is no real skills gap between target school graduates and non-targets, this observation also serves the dual purpose of undermining the NSA’s perceived omnipotence.

Re: Juniper breach mystery starts to clear with new details on hackers and U.S. role

#164
post #80
post #69

Earlier quoted context omitted.

The main leap for whitebox is AES-NI for SSL/TLS offload. Nobody is really using DPDK/NETMAP in OSS products from what I can tell. Netgate is doing TNSR, but its not open source: https://www.netgate.com/tnsr-applications/edge-routing

Check out vyos.net

True, although every time I've tried it out its been fairly garbagey so I never considered it seriously. Its been at least 2 years though, I'll try it again.

Re: Juniper breach mystery starts to clear with new details on hackers and U.S. role

#165
post #83

Earlier quoted context omitted.

The brilliant part is that they did it in a way that remained undetected for so long. And the reason they could do that is because the backdoor already existed.

I wonder how much Intellectual Property was exfiltrated because of this?

Its hubris to think that a national state that can design and execute this kind of attack really needs your IP.

Re: Juniper breach mystery starts to clear with new details on hackers and U.S. role

#167

Earlier quoted context omitted.

Probably pretty chill internally. "The thing we knew would happen and that every expert said would happen happened."

I think you may be surprised, in the NSA they refer to some exploits as NOBUS (nobody but us) where they earnestly believed that only they had the knowledge and capability to find and carry out certain exploits. https://en.wikipedia.org/wiki/NOBUS

They are happy to turn your security into obscurity for their benefit--everything else be damned.

Re: Juniper breach mystery starts to clear with new details on hackers and U.S. role

#168
post #105

Earlier quoted context omitted.

Your best bet is to use things developed entirely in the open. Even if that compromises performance.

That doesn't help if you're trying to be safe from a powerful world government - one with the resources and will to infiltrate an open project for its own ends. It's far less likely that there are US backdoors in Huawei routers (which surely contain Chinese backdoors!) than in any mostly american open-source software you pick.

Huawei routers are well known to be backdoored by the Chinese government. If you’re worried about attacks from nations then you can only build things yourself from scratch, your next best option is things done in the open since the bar for hiding back doors is much higher.

Re: Juniper breach mystery starts to clear with new details on hackers and U.S. role

#169
post #154
post #151

Earlier quoted context omitted.

> Just wanted to acknowledge how brilliant that is. They could have made any other code change, but it was genius using NSA's own backdoor. It is much more plausible that US companies didn't want to name and shame their biggest customer than the Chinese reverse engineering a cryptographic backdoor. This could have been supported by the general NSA/GCHQ efforts to ensure their activies are mis-attributed. The "it was…

> Heck, Microsoft (Longhorn), SecureWorks (Platinum Colony), and Google (GOSSIPGIRL) are the only US companies that have even publicly assigned names to track US linked APT groups. I didn't understand this statement, but it's intrigued me. What are the names for and how do they lead to tracking US-linked APT (advanced, persistent threat a.k.a state sponsored) groups and who's doing the tracking?

The original idea was to assign a name to a unique set of techniques and tools. That way you can collaborate with other organizations and have a common language to describe attackers. Many companies decided to start using their own naming schemes to avoid giving free marketing to the first company to name a group, so you have to do a bit of work to know that all the names I mentioned in my previous post refer to the same group.

CrowdStrike has a naming scheme that includes implied classes for specific countries of origin. For example you may have heard of "FANCY BEAR" which is part of the BEAR family but different from the "COZY BEAR" group. Everyone in the industry knows FANCY BEAR is the Russian GRU and COZY BEAR is Russian SVR, but by using the code names nobody has to come out and say it publicly (or face the consequences of being wrong).

The three companies I named are the only US based ones I know of that have publicly assigned named to US based threat actors. Kaspersky Antivirus (a Russian company) calls them the "Equation Group" due to their love of complex encryption, and the Hungarian government calls them "Tilded Team." If you ask Mandiant or CrowdStrike - they don't exist.

Re: Juniper breach mystery starts to clear with new details on hackers and U.S. role

#170

Earlier quoted context omitted.

Why is that story so far fetched exactly?

That so many hidden/secret chips are being placed on mobos that we are suffering a global chip shortage because of it? Do you really need it explained why that's far fetched? I'm going to let you think on that a bit longer. It should have kicked in by now.

I was referring to the Bloomberg article, you can turn off that incredulity-drive now.
Post reply on HN