Juniper breach mystery starts to clear with new details on hackers and U.S. role
21–30 of 180 posts
Re: Juniper breach mystery starts to clear with new details on hackers and U.S. role
#22This is ground breaking. The NSA made Juniper use a backdoored algorithm, and a foreign adversary hacked into Juniper and changed the backdoor key (essentially). That's surreal.
This smacks way more of "well, what did you expect would happen?" than surrealism. If you introduce a vulnerability, it is nothing but hubris to think that you'll be the only one to leverage the vulnerability.
Re: Juniper breach mystery starts to clear with new details on hackers and U.S. role
#23This is ground breaking. The NSA made Juniper use a backdoored algorithm, and a foreign adversary hacked into Juniper and changed the backdoor key (essentially). That's surreal.
Re: Juniper breach mystery starts to clear with new details on hackers and U.S. role
#24Re: Juniper breach mystery starts to clear with new details on hackers and U.S. role
#25This is ground breaking. The NSA made Juniper use a backdoored algorithm, and a foreign adversary hacked into Juniper and changed the backdoor key (essentially). That's surreal.
> The NSA made Juniper use a backdoored algorithm It's very important to clarify that the NSA didn't make them use it. The DoD required it as terms for future contracts. Juniper grabbed the money in knowing exchange for putting their customers at risk. Why does that distinction matter? It dramatically increases Juniper's culpability in the scheme. If the DoD had actually forced them to use it, that dramatically reduc…
Re: Juniper breach mystery starts to clear with new details on hackers and U.S. role
#26This is ground breaking. The NSA made Juniper use a backdoored algorithm, and a foreign adversary hacked into Juniper and changed the backdoor key (essentially). That's surreal.
No, that's expected behavior and will eventually happen approaching the limit of 100% of the time.
Even worse, a backdoor is often a greater security risk than normal authorization because the backdoor can often access all the data, not just a single user's data.
In short, if you are in government, do not ask for backdoors, if you are in the private sector do not make backdoors. Backdoors are a flawed idea that leads to very bad things for everyone (private sector losses hit government in the pocketbook, too).
Re: Juniper breach mystery starts to clear with new details on hackers and U.S. role
#27We are playing with a slippery slope! A backdoor is a backdoor. Honestly it is getting to the point where open source is the only way to go - imo. I'd like to be able to perform SAST scans and code review on all software that protects my enclaves.
Most open source crypto code just does what NIST and DJB say to do. There's no magic imparted by it being FOSS.
Re: Juniper breach mystery starts to clear with new details on hackers and U.S. role
#28This is ground breaking. The NSA made Juniper use a backdoored algorithm, and a foreign adversary hacked into Juniper and changed the backdoor key (essentially). That's surreal.
Is there a list of exactly what equipment (model numbers) was breached?
Re: Juniper breach mystery starts to clear with new details on hackers and U.S. role
#29This is a great example of why more operators should adopt white box solutions.
It would be interesting to see a refreshed view of what products white-box is able to replace. I recall that Juniper and Cisco were hard to replace for some products because the performance edge was in proprietary ASICs that aren't available to white box builders. I suspect that CPU improvements and things like user-space networking (DPDK and friends) might have closed the gap some, but I haven't seen any recent anal…
Juniper's core routers have neat features in terms of redundancy. failing over a FPC (card with ASIC) to another routing engine(control plane) without downtime or packet flow impact is a big one. Performance might be there on the lower end (Another example is QoS/CoS without impacting performance or queues. These are the kind of things you cannot handle at the CPU without impacting traffic performance, which bites you when you are doing major traffic flows.
Re: Juniper breach mystery starts to clear with new details on hackers and U.S. role
#30Earlier quoted context omitted.
> The NSA made Juniper use a backdoored algorithm It's very important to clarify that the NSA didn't make them use it. The DoD required it as terms for future contracts. Juniper grabbed the money in knowing exchange for putting their customers at risk. Why does that distinction matter? It dramatically increases Juniper's culpability in the scheme. If the DoD had actually forced them to use it, that dramatically reduc…
This is exactly how they "make" a company do something. Look at what happened to the Qwest (IIRC?) CEO to see what happens if you refuse these contracts.
If a company refuses, they are making a decision (more of a gamble). Corporations will almost universally sacrifice customer safety for profit. Especially when they are making a decision between "for sure losing opportunity money" and "maybe losing money after a court case".
That does not mean they aren't liable when things go bad.