Earlier quoted context omitted.
That so many hidden/secret chips are being placed on mobos that we are suffering a global chip shortage because of it? Do you really need it explained why that's far fetched? I'm going to let you think on that a bit longer. It should have kicked in by now.
I was referring to the Bloomberg article, you can turn off that incredulity-drive now.
Juniper breach mystery starts to clear with new details on hackers and U.S. role
171–180 of 180 posts
Re: Juniper breach mystery starts to clear with new details on hackers and U.S. role
#172Earlier quoted context omitted.
Probably pretty chill internally. "The thing we knew would happen and that every expert said would happen happened."
I think you may be surprised, in the NSA they refer to some exploits as NOBUS (nobody but us) where they earnestly believed that only they had the knowledge and capability to find and carry out certain exploits. https://en.wikipedia.org/wiki/NOBUS
Changing the Dual_EC backdoor's public key in shipping products would NOT have been NOBUS.
Re: Juniper breach mystery starts to clear with new details on hackers and U.S. role
#173This is ground breaking. The NSA made Juniper use a backdoored algorithm, and a foreign adversary hacked into Juniper and changed the backdoor key (essentially). That's surreal.
> That's surreal. No, that's expected behavior and will eventually happen approaching the limit of 100% of the time. Even worse, a backdoor is often a greater security risk than normal authorization because the backdoor can often access all the data, not just a single user's data. In short, if you are in government, do not ask for backdoors, if you are in the private sector do not make backdoors. Backdoors are a flaw…
A backdoor rekey attack, if it lets the attacker gain a foothold that allows them continued access after the attack is detected. That is really bad!
Re: Juniper breach mystery starts to clear with new details on hackers and U.S. role
#174This is ground breaking. The NSA made Juniper use a backdoored algorithm, and a foreign adversary hacked into Juniper and changed the backdoor key (essentially). That's surreal.
This needs to be brought up every single time congress proposes encryption backdoors.
Re: Juniper breach mystery starts to clear with new details on hackers and U.S. role
#175Earlier quoted context omitted.
No, you can't trust NIST on security. They've certified algorithms they must have known were deliberately weakened in every generation: DES in the 1970s, the Clipper chip in the 80s, "export-grade" RSA in the 90s, and broken RNGs in the 2000s. The deliberate weakening generally comes from the NSA, but NIST is required to work with them on security standards. A number of reputable security researchers claim that NIST'…
> DES in the 1970s To clarify: the deliberate weakening for DES was literally reducing the key size. There was also some suspicious behaviour with the S-boxes, but that turned out not to be a attack. Sadly, but unsurpisingly, it's not as simple as "Do the oppposite of what the nation state adversary recommends.", although these days independent research is doing well enough that "Ignore them[0] unless they have a non…
In 1975 brute-forcing of 56-bit keys was a NOBUS capability.
Re: Juniper breach mystery starts to clear with new details on hackers and U.S. role
#176We are playing with a slippery slope! A backdoor is a backdoor. Honestly it is getting to the point where open source is the only way to go - imo. I'd like to be able to perform SAST scans and code review on all software that protects my enclaves.
Most open source crypto code just does what NIST and DJB say to do. There's no magic imparted by it being FOSS.
Re: Juniper breach mystery starts to clear with new details on hackers and U.S. role
#177Earlier quoted context omitted.
> Heck, Microsoft (Longhorn), SecureWorks (Platinum Colony), and Google (GOSSIPGIRL) are the only US companies that have even publicly assigned names to track US linked APT groups. I didn't understand this statement, but it's intrigued me. What are the names for and how do they lead to tracking US-linked APT (advanced, persistent threat a.k.a state sponsored) groups and who's doing the tracking?
The original idea was to assign a name to a unique set of techniques and tools. That way you can collaborate with other organizations and have a common language to describe attackers. Many companies decided to start using their own naming schemes to avoid giving free marketing to the first company to name a group, so you have to do a bit of work to know that all the names I mentioned in my previous post refer to the…
Re: Juniper breach mystery starts to clear with new details on hackers and U.S. role
#178For its first 50 years or so NSA had a dual mission: protect the US from spying while spying on others. But these last 20 years they've undermined that first mission. They've now attacked and weakened American technology so many times that you'd be crazy to trust anything the NSA offers to make you more secure. It doesn't help when they lose control of their own hacking tools igniting a major expansion in ransomware.…
> you'd be crazy to trust anything the NSA offers to make you more secure You'd also be crazy to trust anything made by American gear vendors. This is not the only instance of this, just one of the ones for which FVEY got caught. Is non-US gear also compromised? Yeah, probably. But the PLA and the GRU can't physically confine you to an 8x8 steel cage on trumped-up charges predicated on the data they exfil from your n…
In any country, you'll end up in a steel cage regardless of whether you bought your computer or software from the KGB, NSA, or a homemade kit in a bazaar in Nicaragua made by a kid from Chile.
Re: Juniper breach mystery starts to clear with new details on hackers and U.S. role
#179Earlier quoted context omitted.
Well, JunOS is FreeBSD -- the magic is in their proprietary hardware. I'm not aware of open/whitebox solutions that can compete
There’s nothing special with the asics. Juniper makes it’s own Core and Edge routing chips but Arista competes successfully using Broadcom silicon.
Re: Juniper breach mystery starts to clear with new details on hackers and U.S. role
#180Earlier quoted context omitted.
Makes NIST's responses towards DJB in the PQ crypto process have been ... interesting. https://groups.google.com/a/list.nist.gov/g/pqc-forum/c/3mVe...
It's even more interesting that DJB did not care to answer
https://groups.google.com/a/list.nist.gov/g/pqc-forum/c/4baO...