Live data from Hacker News

Juniper breach mystery starts to clear with new details on hackers and U.S. role

bloomberg.com

41–50 of 180 posts

Re: Juniper breach mystery starts to clear with new details on hackers and U.S. role

#41

The intentional weakening of ECC has been an open secret for decades, and it's suspicious that this wasn't known by Juniper. I wonder if they were coerced into including it? https://www.schneier.com/blog/archives/2007/11/the_strange_s...

What does "ECC" mean here?

Re: Juniper breach mystery starts to clear with new details on hackers and U.S. role

#43

The intentional weakening of ECC has been an open secret for decades, and it's suspicious that this wasn't known by Juniper. I wonder if they were coerced into including it? https://www.schneier.com/blog/archives/2007/11/the_strange_s...

What does "ECC" mean here?

I’m guessing it’s elliptic curve cryptography.

https://en.wikipedia.org/wiki/Elliptic-curve_cryptography

Re: Juniper breach mystery starts to clear with new details on hackers and U.S. role

#44
> Members of a hacking group linked to the Chinese government called APT 5 hijacked the NSA algorithm

Just wanted to acknowledge how brilliant that is. They could have made any other code change, but it was genius using NSA's own backdoor.

NSA advocated for that backdoor to be included in the standards. The US government then would be embarrassed and would want to cover up any issues related to it, including the fact that it was taken over by someone else!

Gotta wonder what that Monday morning meeting was like at the NSA when they realized what had happened.

Re: Juniper breach mystery starts to clear with new details on hackers and U.S. role

#45
post #42
post #3

This is ground breaking. The NSA made Juniper use a backdoored algorithm, and a foreign adversary hacked into Juniper and changed the backdoor key (essentially). That's surreal.

It's Bloomberg. Be skeptical.

I'm surprised we haven't seen an article explaining that the chip shortage is due to so many hidden chips being secretly placed on mobos used by the largest vendors.

Re: Juniper breach mystery starts to clear with new details on hackers and U.S. role

#46
post #25

Earlier quoted context omitted.

> The NSA made Juniper use a backdoored algorithm It's very important to clarify that the NSA didn't make them use it. The DoD required it as terms for future contracts. Juniper grabbed the money in knowing exchange for putting their customers at risk. Why does that distinction matter? It dramatically increases Juniper's culpability in the scheme. If the DoD had actually forced them to use it, that dramatically reduc…

Were Juniper informed of the vulnerability at the time they made the decision? It appears not.

The vulnerability had been disclosed in 2007 by several independent researchers. It had also been patented by Certicom.

Re: Juniper breach mystery starts to clear with new details on hackers and U.S. role

#47
For its first 50 years or so NSA had a dual mission: protect the US from spying while spying on others. But these last 20 years they've undermined that first mission. They've now attacked and weakened American technology so many times that you'd be crazy to trust anything the NSA offers to make you more secure. It doesn't help when they lose control of their own hacking tools igniting a major expansion in ransomware.

I don't think America can ever recover from this breach of trust. Maybe NSA just needs to be shut down entirely. Or at least redefined explicitly as an adversarial agency to everyone.

Re: Juniper breach mystery starts to clear with new details on hackers and U.S. role

#48

The intentional weakening of ECC has been an open secret for decades, and it's suspicious that this wasn't known by Juniper. I wonder if they were coerced into including it? https://www.schneier.com/blog/archives/2007/11/the_strange_s...

The article tells us "the Pentagon tied some future contracts for Juniper specifically to the use of Dual Elliptic Curve". That's not outright coercion but it's a significant incentive. Hell, RSA allowed itself to be corrupted for a measly $10M. https://www.theverge.com/2013/12/20/5231006/nsa-paid-10-mill...

Re: Juniper breach mystery starts to clear with new details on hackers and U.S. role

#49
Bloomberg at the frontline of "having no idea how anything works at all".

When the NSA designed DEC, they primed it with constants, that you'd need to know to break the encryption with low effort.

Somebody discovered that and made it known publicly.

So now before the rumors evolve into actual security engineers looking into it, the NSA creates a scapegoat APT, that "altered" some "code" at Juniper.

Of course nobody finds out, who those APT are, because attribution is 1% more accurate than astrology.

Re: Juniper breach mystery starts to clear with new details on hackers and U.S. role

#50
The article mentions the Clipper Chip briefly but doesn't touch on what was widely believed at the time -- that the NSA and their political counterparts went completely silent on using legislation to backdoor encryption algorithms not because they lost the fight but because they had found a better way.
Post reply on HN