Live data from Hacker News

Juniper breach mystery starts to clear with new details on hackers and U.S. role

bloomberg.com

31–40 of 180 posts

Re: Juniper breach mystery starts to clear with new details on hackers and U.S. role

#31
post #23

Earlier quoted context omitted.

Is there a list of exactly what equipment (model numbers) was breached?

It is software not hardware, so whatever model used the software.

Theoretically you can run any software on any hardware so all hardware in the world is infected.

No, I'm not being serious. Obviously what dheera is referring to is not software vs hardware but rather what hardware is affected. To comment that it's the hardware that is running the software that is infected is hardly useful.

Re: Juniper breach mystery starts to clear with new details on hackers and U.S. role

#32

Earlier quoted context omitted.

It is software not hardware, so whatever model used the software.

Theoretically you can run any software on any hardware so all hardware in the world is infected. No, I'm not being serious. Obviously what dheera is referring to is not software vs hardware but rather what hardware is affected. To comment that it's the hardware that is running the software that is infected is hardly useful.

Right, I'm wondering what models were designed to officially run the software that was infected, and if there are models that are known (by source code, reverse engineering or otherwise) to run uninfected firmware.

Re: Juniper breach mystery starts to clear with new details on hackers and U.S. role

#33
post #3

This is ground breaking. The NSA made Juniper use a backdoored algorithm, and a foreign adversary hacked into Juniper and changed the backdoor key (essentially). That's surreal.

What if an insider helped the foreign adversary gain access?

Does that change anything with the NSA getting NIST, DoD, and later mfgs to go along with an algorithm that had two backdoors?

Re: Juniper breach mystery starts to clear with new details on hackers and U.S. role

#34
post #27
post #14

Earlier quoted context omitted.

Most open source crypto code just does what NIST and DJB say to do. There's no magic imparted by it being FOSS.

I agree and that's pretty sad. FOSS gives the opportunity to code review.

Heart bleed is still the biggest point against your argument.

The key word you correctly used is OPPORTUNITY.

I like smaller localized governance, but would not be opposed at all to a federal subsidized program for security bugs and open source development of algorithms and code for commonly required tasks.

Re: Juniper breach mystery starts to clear with new details on hackers and U.S. role

#35
post #32

Earlier quoted context omitted.

Theoretically you can run any software on any hardware so all hardware in the world is infected. No, I'm not being serious. Obviously what dheera is referring to is not software vs hardware but rather what hardware is affected. To comment that it's the hardware that is running the software that is infected is hardly useful.

Right, I'm wondering what models were designed to officially run the software that was infected, and if there are models that are known (by source code, reverse engineering or otherwise) to run uninfected firmware.

Basically any Juniper NetScreen (SSG-xxx) device, since it was ScreenOS that was modified by the attackers.

Re: Juniper breach mystery starts to clear with new details on hackers and U.S. role

#36
post #3

This is ground breaking. The NSA made Juniper use a backdoored algorithm, and a foreign adversary hacked into Juniper and changed the backdoor key (essentially). That's surreal.

> That's surreal. No, that's expected behavior and will eventually happen approaching the limit of 100% of the time. Even worse, a backdoor is often a greater security risk than normal authorization because the backdoor can often access all the data, not just a single user's data. In short, if you are in government, do not ask for backdoors, if you are in the private sector do not make backdoors. Backdoors are a flaw…

[deleted]

Re: Juniper breach mystery starts to clear with new details on hackers and U.S. role

#37
post #7

How many more back-doors like that are out there that are not in public domain yet? And can we trust standard committees who, funded by public, put back doors in encryption and weaken security of public services?

Well one heuristic to look at is how much proprietary and closed-source software is out there, and then make a rough estimate, say 3% of proprietary software has some sort of backdoor or malicious payload in it.

What you have to ask, is why is certain software proprietary? Most of it is innocent, but sometimes it's closed for evil reasons.

Re: Juniper breach mystery starts to clear with new details on hackers and U.S. role

#38
post #36

Earlier quoted context omitted.

> That's surreal. No, that's expected behavior and will eventually happen approaching the limit of 100% of the time. Even worse, a backdoor is often a greater security risk than normal authorization because the backdoor can often access all the data, not just a single user's data. In short, if you are in government, do not ask for backdoors, if you are in the private sector do not make backdoors. Backdoors are a flaw…

[deleted]

[deleted]

Re: Juniper breach mystery starts to clear with new details on hackers and U.S. role

#39
post #7

How many more back-doors like that are out there that are not in public domain yet? And can we trust standard committees who, funded by public, put back doors in encryption and weaken security of public services?

Can almost certainly be sure CISCO is affected by something similar.

Re: Juniper breach mystery starts to clear with new details on hackers and U.S. role

#40
post #7

How many more back-doors like that are out there that are not in public domain yet? And can we trust standard committees who, funded by public, put back doors in encryption and weaken security of public services?

No, you can't trust NIST on security. They've certified algorithms they must have known were deliberately weakened in every generation: DES in the 1970s, the Clipper chip in the 80s, "export-grade" RSA in the 90s, and broken RNGs in the 2000s.

The deliberate weakening generally comes from the NSA, but NIST is required to work with them on security standards.

A number of reputable security researchers claim that NIST's misdeeds were all unintentional and they've learned their lesson and there won't be any more backdoors. Perhaps. Ultimately they serve the US administration, so in the long term it depends on whether future administrations actually want everyone to have unbreakable cryptography. Doesn't seem like a safe thing to count on.

Post reply on HN