Live data from Hacker News

NSA Reportedly Intercepts And Alters Routers And Servers Exported From U.S.

techcrunch.com

31–40 of 47 posts

Re: NSA Reportedly Intercepts And Alters Routers And Servers Exported From U.S.

#31
post #30

How can we protect ourselves from this type of interception? It seems impossible. Why would any non-american customers buy US made devices? Any protections that are added can/will be bypassed if the US gov gets physical access (or even remote).

Just about the time of the previous revelation of computers from outside the US being intercepted by TLAs, my new Lenovo was delayed for a long time in some customs facility (according to UPS tracking). Software is not a concern as I blew away the preinstalled and put a relatively trusted OS on. But hardware - I haven't had time to look into it but I'm still wanting some sort of guide on what to look for after unscre…

The scary part is that blowing away the OS install won't save you completely. There are BIOS, firmware attacks, to name a couple. Take a look at the following link with information about persistent root access via hard drive firmware hacking. Even if you reinstall the OS, your box will continue to be owned:

http://spritesmods.com/?art=hddhack&page=1

Re: NSA Reportedly Intercepts And Alters Routers And Servers Exported From U.S.

#32
post #6

So is it safe to assume every Intel or AMD CPU also likely has hidden capabilities waiting to be exploited by the NSA?

Not just waiting....

If you have the ability to insert backdoors on widely used hardware with no realistic alternative implementations, without anyone other than a very select few (who all have plenty to lose if they reveal anything) knowing about it; AND the only thing you'll use it for is National Security (preventing someone from building a nuke to drop on your country), why would you NOT go through with it?

Re: NSA Reportedly Intercepts And Alters Routers And Servers Exported From U.S.

#33
post #27

How much hardware is actually made in the USA anymore? Most HW is manufactured in Taiwan, China, Korea, Thailand, Malaysia or maybe Mexico. I used to work for a router manufacturer that manufactured all of its equipment in Taiwan and Mexico. When we shipped to someone in Europe(for example) we shipped directly from Taiwan to Europe, not through the US. So I have to wonder how much of this stuff the NSA could actually…

I simply cannot fathom how the NSA could hope to intercept and physically mess with every single piece of $10 to $10,000 router sold. If true, and I have a hard time believing it is not, either this is done at the design level (and not just on router chips), or only for big ticket backbone and/or enterprise equipment.

It doesn't have to be every $10 router. Plant one compromised router at each router factory, check when primary target X, Y or Z orders routers, intercept that shipment and hack each router.

Re: NSA Reportedly Intercepts And Alters Routers And Servers Exported From U.S.

#34

Hrm, guess I wont buy American any more.

"Do you mean a car designed in the US and built in China, or a Japanese car built in Ohio?" I'm pretty sure that given how few choices of mainstream hardware there are you are screwed no matter what you buy.

Oh certainly, I'm not saying I'm there's a need to be a fanatical purist and go through component that goes into my equipment.

I'll just stop purchasing the bulk from US supplies and subsidiaries it's not like there aren't alternative suppliers with good prices.

Re: NSA Reportedly Intercepts And Alters Routers And Servers Exported From U.S.

#35
post #18
post #10

Earlier quoted context omitted.

What are the hidden router capabilities being exploited here? What piece of COTS hardware couldn't be exploited by an attacker with unlimited physical access to it prior to delivery?

Indeed. Somehow a story about NSA tampering with devices after manufacture is being twisted into "all commercial products are deliberately backdoored". If you actually use logic, these are separate issues. Actually, if anything, the story is proof that the routers are not backdoored from the start, otherwise why would they have to intercept shipments?

Actually, if anything, the story is proof that the routers are not backdoored from the start

Let me preface my response by saying I think there are probably more non-malicious (accidental) vulnerabilities than intentional backdoors.

Schneier has seen many of the original documents, and his constant refrain is that NSA programs are robust -- that they have multiple totally unrelated ways to accomplish any one goal. Quoting one of his articles:

"First and foremost, the surveillance state is robust. It is robust politically, legally, and technically. I can name three different NSA programs to collect Gmail user data. These programs are based on three different technical eavesdropping capabilities. They rely on three different legal authorities. They involve collaborations with three different companies. And this is just Gmail. The same is true for cell phone call records, Internet chats, cell-phone location data."

https://www.schneier.com/essay-469.html

The takeaway is that, knowing the NSA has capability A doesn't prove they lack capabilities B, C, D...Z.

Re: NSA Reportedly Intercepts And Alters Routers And Servers Exported From U.S.

#37

How much hardware is actually made in the USA anymore? Most HW is manufactured in Taiwan, China, Korea, Thailand, Malaysia or maybe Mexico. I used to work for a router manufacturer that manufactured all of its equipment in Taiwan and Mexico. When we shipped to someone in Europe(for example) we shipped directly from Taiwan to Europe, not through the US. So I have to wonder how much of this stuff the NSA could actually…

Anything that's shipped from the US, basically. From the slides released with Greenwald's new book today: https://i.imgur.com/lCM0apx.png Here's the source, but be warned that this is a 90 MB pdf: http://hbpub.vo.llnwd.net/o16/video/olmk/holt/greenwald/NoPl...

I get the feeling that if every router was being intercepted, that picture would look more like a giant series of assembly lines rather than three people casually sitting around a Cisco box.

Re: NSA Reportedly Intercepts And Alters Routers And Servers Exported From U.S.

#38

Earlier quoted context omitted.

Anything that's shipped from the US, basically. From the slides released with Greenwald's new book today: https://i.imgur.com/lCM0apx.png Here's the source, but be warned that this is a 90 MB pdf: http://hbpub.vo.llnwd.net/o16/video/olmk/holt/greenwald/NoPl...

I get the feeling that if every router was being intercepted, that picture would look more like a giant series of assembly lines rather than three people casually sitting around a Cisco box.

Guess I should've been clearer: any equipment they're interested in that ships from the US is at risk. They don't need to go after all equipment. They only need to go after equipment being shipped to backbone providers abroad, and specific targets they are interested in that are "tough to crack."

Further, if one believes that TAO is limiting themselves to terrorists buying Cisco equipment, I have a bridge to sell you. That's absurd considering they produly boast about their economic espionage, their spying on activists such as Wikileaks supporters and other "radicals," and their partners bragging about how they DDoS IRC chat rooms of hacktivists.

One example: http://justsecurity.org/2013/11/29/nsa-sexint-abuse-youve-wa...

All of this is summarized in Greenwald's new book.

Re: NSA Reportedly Intercepts And Alters Routers And Servers Exported From U.S.

#39

Earlier quoted context omitted.

I get the feeling that if every router was being intercepted, that picture would look more like a giant series of assembly lines rather than three people casually sitting around a Cisco box.

Guess I should've been clearer: any equipment they're interested in that ships from the US is at risk. They don't need to go after all equipment. They only need to go after equipment being shipped to backbone providers abroad, and specific targets they are interested in that are "tough to crack." Further, if one believes that TAO is limiting themselves to terrorists buying Cisco equipment, I have a bridge to sell you…

I don't expect them to be limiting themselves to terrorists - they're a foreign intelligence agency. I expect them to be gathering info on foreign governments, militaries, etc. (along with spying on terrorists).

I've written about the NSA porno article before, so I'll just post the link to that thread[1]. The TLDR is that Greenwald seems to have left a good deal out of his reporting in order to both sensationalize and avoid discrediting his own argument. I haven't read his new book; maybe he addresses it in there.

[1] https://news.ycombinator.com/item?id=6885325

Re: NSA Reportedly Intercepts And Alters Routers And Servers Exported From U.S.

#40

Earlier quoted context omitted.

Guess I should've been clearer: any equipment they're interested in that ships from the US is at risk. They don't need to go after all equipment. They only need to go after equipment being shipped to backbone providers abroad, and specific targets they are interested in that are "tough to crack." Further, if one believes that TAO is limiting themselves to terrorists buying Cisco equipment, I have a bridge to sell you…

I don't expect them to be limiting themselves to terrorists - they're a foreign intelligence agency. I expect them to be gathering info on foreign governments, militaries, etc. (along with spying on terrorists). I've written about the NSA porno article before, so I'll just post the link to that thread[1]. The TLDR is that Greenwald seems to have left a good deal out of his reporting in order to both sensationalize an…

No, but that's their justification the vast majority of the time. They don't limit it to foreign governments or militaries either. They do engage in economic espionage, fact. They do single out anyone they don't like which isn't limited to terrorists in these campaigns: "radicals", among them Wikileaks supports, fact.

Stewart Baker has discredited himself[1], his opinion is worth jack shit frankly. I wouldn't trust anything he says, not only because he was behind many of these programs as council but also because of Eben Moglen's interactions with him during the almost-prosecution of Phil Zimmerman, and suggest you do the same.

That the documents are 'sensationalized' is the favorite refuge of NSA goons: when Keith Alexander's comment about collecting it all became public, SEXINT, PRISM, etc. He talks about all of those and leaves no doubt that this characterization is horse shit after the third chapter.

[1] http://www.skatingonstilts.com/skating-on-stilts/2014/04/hid...

Post reply on HN