Live data from Hacker News

Snowden leak: Cavium networking hardware may contain NSA backdoor

twitter.com

401–410 of 628 posts

Re: Snowden leak: Cavium networking hardware may contain NSA backdoor

#401

Earlier quoted context omitted.

crypto doesn't matter if chip itself has backdoor that will grant root access on some "magic" packet

Crypto matters for exactly this reason. All my internet traffic passes through unsafe middle-boxes, it is TLS and DH that make sure I can pass through untrusted middlemen without them knowing what is going on.

Cavium chips are installed on security appliances (lol): think Palo alto firewall, fortinet firewall, F5 Big-IP etc.

they will see your traffic in plain text by design

Re: Snowden leak: Cavium networking hardware may contain NSA backdoor

#402

Earlier quoted context omitted.

Snowden leaked a shit ton of documents, the vast majority of which had absolutely nothing to do with any kind of NSA wrongdoing. Journalists then had to go through and try to figure out what these documents actually meant (which they frequently misunderstood). Obviously they're still doing it to today.

>Snowden leaked a shit ton of documents, the vast majority of which had absolutely nothing to do with any kind of NSA wrongdoing Like how NSA collects a shit ton of data on citizens... the vast majority of which has absolutely nothing to do with any kind of wrongdoing. I'm only pointing this out because your comment has a negative tone towards what Snowden did.

Making a strawman argument doesn't point anything out.

Re: Snowden leak: Cavium networking hardware may contain NSA backdoor

#403
post #45

Earlier quoted context omitted.

I wonder if MikroTik would be compromised- they’re Latvian and don’t necessarily have to bow to the NSA.

There's been plenty of remote 0days in MikroTik's products. At one point people were paying a pretty penny for them.

I think it’s worth noting that these vulnerabilities affected devices which had their management page open to the internet, which is universally known as a bad idea. At least the ones I’ve seen.

There is a big difference between an exploit affecting all devices vs a subset which requires a specific not-best-practice configuration. Regardless, still good to be aware they exist.

Re: Snowden leak: Cavium networking hardware may contain NSA backdoor

#405
post #143

Earlier quoted context omitted.

AWS support is pretty fucking terrible generally. We’re a very high rolling enterprise customer and it’s pretty obvious that some of their shit is being managed by two guys in a shed somewhere who don’t talk to each other.

Have you had the pleasure of working with Azure? I'll take AWS any day over that dumpster fire.

We work with Azure and don't have any major complaints about it - what were your issues?

Re: Snowden leak: Cavium networking hardware may contain NSA backdoor

#406
post #239

Earlier quoted context omitted.

Well, there's several Cavium devices that support the deprecated/back-doored Hash_DRBG. For example, these devices were validated for the completely appropriately named "SonicOS 6.2.5 for TZ, SM and NSA". Gotta appreciate the irony. Cavium CN7020 Hash DRBG Cavium CN7130 Hash DRBG Cavium Octeon Plus CN66XX Family Hash DRBG Cavium Octeon Plus CN68XX Family Hash DRBG I don't know if that's hardware support or just a sof…

Except Hash_DRBG is neither deprecated nor backdoored. See NIST SP 800-90A Rev. 1 section 10.1.1.1 for description of the algorithm.

Well, true.. the Hash_DRBG hashing algorithm remains. But it's rather likely that previous FIPS validations occurred utilizing the actual backdoored and deprecated algorithm as an input to the Hash_DRBG, rendering it's security properties suspect.

In NIST SP 800-90A Rev. 1, the HASH_DRBG section has been significantly updated to that effect.

For instance, Appendix E: (Informative) Revisions.

Section 10: Section 10 now includes a link to the DRBG test vectors on the NIST website. Sections 10.1, 10.1.1 and 10.1.2 now include short discussions about selecting hash functions to support the DRBG's intended security strength. The Dual_EC_DRBG has been removed, and section numbers adjusted accordingly.

Re: Snowden leak: Cavium networking hardware may contain NSA backdoor

#407

How the NSA successfully manage to prevent the Washington Post and friends from discovering and reporting on this malicious backdoor? They've been sitting on these documents for a decade. Are the journalists just that *uncurious* about the deep contents of the documents they hold exclusive access to? Was this some kind of organizational failing?

I personally suspect that security services visited the newspapers a few days after the leak [1], and ever since then, every article has been about stuff that wouldn't be a surprise to rival security services.

Sure - it was a surprise to the public. But rival security services I'm sure would expect US controlled backdoors in US made technology.

[1]: https://www.theguardian.com/uk-news/2014/jan/31/footage-rele...

Re: Snowden leak: Cavium networking hardware may contain NSA backdoor

#408
post #246

Earlier quoted context omitted.

> Last I heard, she said they convinced her she wasn’t allowed to ask corporate lawyers for guidance. To me, anyone purporting to be an official government employee advising you that you cannot speak to an attorney throws up so many red flags, that I just can't imagine it being anything but sinister.

If an official government employee is already apparently breaking the law and also threatening you personally, you need to ask yourself whether they'll worry about continuing to break the law in order to make good on their threats. Note that none of the people that coerced Mayer into breaking the law have been disciplined or even named, so I guess they didn't need to worry about such things after all. I've heard EFF…

It is they will need to make the police not so bad.

Make it illegal for police to lie about their intentions and the facts of the case (although perhaps they should be permitted to hide some of the facts of the case (although they cannot hide what you are actually accused of, or anything like that, if they are actually arresting you (since otherwise they should have no authority to arrest anyone)), and anyone (whether police or not) should always be permitted to claim "I don't know").

If you lie (or make a mistake) to the police while you are being interrogated, that should not be illegal (although making a false police report (while you are not being interrogated) would still be illegal).

Furthermore, any claim they make that, if valid, would not authorize them to do what they are doing to you, makes what they are doing illegal in that instance. For example, if you ask them if they are police and they say they are not police then they have no authority to arrest you (although they can still make a citizen's arrest (for situations where that is permitted, so, not necessarily all of the things that the police might arrest you for), or to call some of the police other than themself (using the methods that ordinary people would use, not the ones reserved for police), etc.

This isn't even half of enough to fix the problems with police, but it is a start.

Re: Snowden leak: Cavium networking hardware may contain NSA backdoor

#409

Earlier quoted context omitted.

If you're not under the threat cone of nation state surveillance (like trying to exfiltrate the radar-asborbing paint formula on the F35) then I wouldn't be too concerned. "That's not the point! It's about privacy!" Sure. I'll choose it ignore the fact that our civilization is somehow still functioning in a post-nuclear world.

> If you're not under the threat cone of nation state surveillance The average reader may be surprised by how far this cone can extend in some circumstances. It has been established that the NSA conducts industrial espionage [0], under the cover of national security [1]. To what degree the term "national security" narrows down the scope of any surveillance measures is likely unfamiliar to the laymen, but an NSA repre…

The NSA has been caught lying before (see: the Snowden leaks) so I wouldn't trust them to be forthcoming about their industrial espionage, if they are engaging in it. Of course they'd deny it.

Re: Snowden leak: Cavium networking hardware may contain NSA backdoor

#410

Earlier quoted context omitted.

Ayup. We use AWS CloudHSM to hold our private signing keys for deploying field upgrades to our hardware. And when we break the CI scripts I see Cavium in the AWS logs. Now I gotta take this to our security team and figure out what to do.

Nobody cares. If caring gets in the way of easy money. Spoiler...it does.

more accurately, nobody (with sufficient agency to act) cares.

you wouldn’t be cynical if you didn’t care, or felt able to do anything about it.

Post reply on HN