Live data from Hacker News

Juniper breach mystery starts to clear with new details on hackers and U.S. role

bloomberg.com

171–180 of 180 posts

Re: Juniper breach mystery starts to clear with new details on hackers and U.S. role

#171

Earlier quoted context omitted.

That so many hidden/secret chips are being placed on mobos that we are suffering a global chip shortage because of it? Do you really need it explained why that's far fetched? I'm going to let you think on that a bit longer. It should have kicked in by now.

I was referring to the Bloomberg article, you can turn off that incredulity-drive now.

The Heart of Gold has the improbability drive, while its sister ship the Heart of Silver has the incredulity drive. I like it. I hadn't heard that one before.

Re: Juniper breach mystery starts to clear with new details on hackers and U.S. role

#172

Earlier quoted context omitted.

Probably pretty chill internally. "The thing we knew would happen and that every expert said would happen happened."

I think you may be surprised, in the NSA they refer to some exploits as NOBUS (nobody but us) where they earnestly believed that only they had the knowledge and capability to find and carry out certain exploits. https://en.wikipedia.org/wiki/NOBUS

Use of the NSA's private key for the Dual_EC's backdoor would have been NOBUS (unless it were stolen).

Changing the Dual_EC backdoor's public key in shipping products would NOT have been NOBUS.

Re: Juniper breach mystery starts to clear with new details on hackers and U.S. role

#173
post #3

This is ground breaking. The NSA made Juniper use a backdoored algorithm, and a foreign adversary hacked into Juniper and changed the backdoor key (essentially). That's surreal.

> That's surreal. No, that's expected behavior and will eventually happen approaching the limit of 100% of the time. Even worse, a backdoor is often a greater security risk than normal authorization because the backdoor can often access all the data, not just a single user's data. In short, if you are in government, do not ask for backdoors, if you are in the private sector do not make backdoors. Backdoors are a flaw…

Keep in mind that an attacker that can change source code can add a backdoor where there is none. Backdoors are dangerous because their keys can leak. In the case of Dual_EC a leak would have been particularly dangerous because the attack enabled by having the backdoor's key is passive, so not easily detected.

A backdoor rekey attack, if it lets the attacker gain a foothold that allows them continued access after the attack is detected. That is really bad!

Re: Juniper breach mystery starts to clear with new details on hackers and U.S. role

#174
post #3

This is ground breaking. The NSA made Juniper use a backdoored algorithm, and a foreign adversary hacked into Juniper and changed the backdoor key (essentially). That's surreal.

This needs to be brought up every single time congress proposes encryption backdoors.

It's been done before. Back in the oughts when Congress was proposing CALEA, many told them it was a bad idea.

Re: Juniper breach mystery starts to clear with new details on hackers and U.S. role

#175
post #40

Earlier quoted context omitted.

No, you can't trust NIST on security. They've certified algorithms they must have known were deliberately weakened in every generation: DES in the 1970s, the Clipper chip in the 80s, "export-grade" RSA in the 90s, and broken RNGs in the 2000s. The deliberate weakening generally comes from the NSA, but NIST is required to work with them on security standards. A number of reputable security researchers claim that NIST'…

> DES in the 1970s To clarify: the deliberate weakening for DES was literally reducing the key size. There was also some suspicious behaviour with the S-boxes, but that turned out not to be a attack. Sadly, but unsurpisingly, it's not as simple as "Do the oppposite of what the nation state adversary recommends.", although these days independent research is doing well enough that "Ignore them[0] unless they have a non…

This. DES was strengthened against differential cryptanalysis, a technique not discovered by the public for over a decade. https://en.wikipedia.org/wiki/Differential_cryptanalysis

In 1975 brute-forcing of 56-bit keys was a NOBUS capability.

Re: Juniper breach mystery starts to clear with new details on hackers and U.S. role

#176
post #14
post #10

We are playing with a slippery slope! A backdoor is a backdoor. Honestly it is getting to the point where open source is the only way to go - imo. I'd like to be able to perform SAST scans and code review on all software that protects my enclaves.

Most open source crypto code just does what NIST and DJB say to do. There's no magic imparted by it being FOSS.

And you still need to review the code yourself and review the compiler's code, and all the object code produced, and test it, and...

Re: Juniper breach mystery starts to clear with new details on hackers and U.S. role

#177
post #169
post #154

Earlier quoted context omitted.

> Heck, Microsoft (Longhorn), SecureWorks (Platinum Colony), and Google (GOSSIPGIRL) are the only US companies that have even publicly assigned names to track US linked APT groups. I didn't understand this statement, but it's intrigued me. What are the names for and how do they lead to tracking US-linked APT (advanced, persistent threat a.k.a state sponsored) groups and who's doing the tracking?

The original idea was to assign a name to a unique set of techniques and tools. That way you can collaborate with other organizations and have a common language to describe attackers. Many companies decided to start using their own naming schemes to avoid giving free marketing to the first company to name a group, so you have to do a bit of work to know that all the names I mentioned in my previous post refer to the…

You've opened the doors to a fascinating world for me.

Re: Juniper breach mystery starts to clear with new details on hackers and U.S. role

#178
post #72

For its first 50 years or so NSA had a dual mission: protect the US from spying while spying on others. But these last 20 years they've undermined that first mission. They've now attacked and weakened American technology so many times that you'd be crazy to trust anything the NSA offers to make you more secure. It doesn't help when they lose control of their own hacking tools igniting a major expansion in ransomware.…

> you'd be crazy to trust anything the NSA offers to make you more secure You'd also be crazy to trust anything made by American gear vendors. This is not the only instance of this, just one of the ones for which FVEY got caught. Is non-US gear also compromised? Yeah, probably. But the PLA and the GRU can't physically confine you to an 8x8 steel cage on trumped-up charges predicated on the data they exfil from your n…

It is entirely nonsensical to me that buying from alibaba would save you from an overly-inquisitive domestic government.

In any country, you'll end up in a steel cage regardless of whether you bought your computer or software from the KGB, NSA, or a homemade kit in a bazaar in Nicaragua made by a kid from Chile.

Re: Juniper breach mystery starts to clear with new details on hackers and U.S. role

#179
post #123

Earlier quoted context omitted.

Well, JunOS is FreeBSD -- the magic is in their proprietary hardware. I'm not aware of open/whitebox solutions that can compete

There’s nothing special with the asics. Juniper makes it’s own Core and Edge routing chips but Arista competes successfully using Broadcom silicon.

There are switches out there by either Juniper or Cisco (can't remember which job I used them at) which actually have ARM CPUs on each switchport for one hardware acceleration feature :)

Re: Juniper breach mystery starts to clear with new details on hackers and U.S. role

#180
post #155
post #108

Earlier quoted context omitted.

Makes NIST's responses towards DJB in the PQ crypto process have been ... interesting. https://groups.google.com/a/list.nist.gov/g/pqc-forum/c/3mVe...

It's even more interesting that DJB did not care to answer

He had answered, in advance-- in the form of a formal complaint because the substance of NIST's message (the complaint that DJB had hung a carrot of 'attacks' in front of them in private but hadn't delivered a publication 'on time') had been previously stated by one of their staff. He published the formal complaint today:

https://groups.google.com/a/list.nist.gov/g/pqc-forum/c/4baO...

Post reply on HN