Earlier quoted context omitted.
In the US, we have this passionate fantasy about Woodward and Bernstein and the Post and the Pulitzer and the movie and Redford and Hoffman and the Academy Award, about how the Press played the part of the "fourth estate" as the Founders intended, and rooted out a corrupt politician, and forced him to resign. It's all bullshit. The people who broke into the Watergate Hotel were CIA, Woodward was formerly CIA, and "De…
Wow, the deep state is so powerful that they got Nixon to say on tape that he was going to try to get the CIA to falsely use national security as an excuse to stonewall an FBI investigation. Poor innocent Nixon was no match for their telepathic powers.
Snowden leak: Cavium networking hardware may contain NSA backdoor
451–460 of 628 posts
Re: Snowden leak: Cavium networking hardware may contain NSA backdoor
#452Earlier quoted context omitted.
That doesn't prove anything. You're just saying that Huawei could theoretically be compromised, but the above commenter asked for evidence.
They are compromised in terms of governance, and their legal environment is the proof of this. Nobody has ever claimed that Huawei devices have backdoors. The issue is that the supply chain is compromised by legal means, not the hardware or software currently being shipped has technical vulnerabilities.
Just a few comments up in this thread, someone claimed definitively that Huawei equipment has been proven to be compromised, meaning backdoored.
> They are compromised in terms of governance
We don't have any known examples of Huawei being forced by the Chinese government to compromise its equipment. This is still a wholly theoretical discussion. In contrast, we know that the US government has inserted backdoors into American (and not just American) equipment, and is able to secretly compel companies to comply with US spying.
Re: Snowden leak: Cavium networking hardware may contain NSA backdoor
#453Earlier quoted context omitted.
As does the USA, so we shouldn't be using Windows or Yubico either, or virtually any other software/hardware from any other vendor because there's few countries that let you do illegal-over-there things without having a mechanism to force you It's a "pick your poison" situation, not a "they've got national security letters and so you can't trust them" one
This is why security is not a "one size fits all" exercise. The first thing you must do is define your threat model. The reason the Chinese government doesn't want to build their telecom system on Cisco hardware is the same exact reason the USG doesn't want to do the same with Huawei hardware. Because neither government is delusional enough to think that parts/service/updates wouldn't be immediately sanctioned in tim…
It's not symmetrical. Since Trump, the US has been extraordinarily aggressive in its use of sanctions against Chinese companies, whereas China has been very reluctant to retaliate directly.
The US has sanctioned hundreds of Chinese tech companies. China has only recently begun to retaliate in kind, but has so far only sanctioned a few US companies (Micron is the only prominent example that comes to mind).
Re: Snowden leak: Cavium networking hardware may contain NSA backdoor
#454Earlier quoted context omitted.
In a world where local PD can kick my door in, shoot me in the face, and the news will report that I had it coming because I own a gun, I find it hard to care that the IC can burn a technical access backdoor to access my private data.
Integrated circuit?
Re: Snowden leak: Cavium networking hardware may contain NSA backdoor
#455More interestingly, Cavium (now Marvell) also designed and manufactured the HSMs which are used by the top cloud providers (such as AWS, GCP, possibly Azure too), to hold the most critical private keys: https://www.prnewswire.com/news-releases/caviums-liquidsecur...
Narrative control and information modeling is so powerful it’s scary.
Re: Snowden leak: Cavium networking hardware may contain NSA backdoor
#456Earlier quoted context omitted.
I'd be surprised if you get anything more than generic statements about how they take security very seriously and they are open to suggestions, but avoid addressing the mentioned concerns directly (and this applies to all cloud providers out there, not just AWS). I'm sure a few others here would like to see their response as well.
wouldnt such a backdoor invalidate all promises made by external audits e.g. https://cloud.google.com/security/compliance/offerings and more importantly wouldn't it violate safe harbor agreement with the EU or whatever sham this safe-harbor was replaced with?
Re: Snowden leak: Cavium networking hardware may contain NSA backdoor
#457Earlier quoted context omitted.
To save others a goog: https://en.wikipedia.org/wiki/Lavabit > Lavabit is an open-source encrypted webmail service, founded in 2004. The service suspended its operations on August 8, 2013 after the U.S. Federal Government ordered it to turn over its Secure Sockets Layer (SSL) private keys, in order to allow the government to spy on Edward Snowden's email
> He also wrote that in addition to being denied a hearing about the warrant to obtain Lavabit's user information, he was held in contempt of court. The appellate court denied his appeal due to no objection, however, he wrote that because there had been no hearing, no objection could have been raised. His contempt of court charge was also upheld on the ground that it was not disputed; similarly, he was unable to disp…
Re: Snowden leak: Cavium networking hardware may contain NSA backdoor
#458Earlier quoted context omitted.
Level 1 is pretty easy to meet IIRC. It's 2-4 that are hard, with pretty much no Level 4 certified ones on market I believe?
The IBM one for z was level 4 I think.. Yes: https://www.ibm.com/docs/en/cryptocards?topic=4768-overview
If I wanted to store an important long term key in a secure facility, I would worry, first and foremost, about software attacks, attacks doable over a network, malicious firmware attacks, and maybe passively observed side channel attacks. Physical attacks would be a rather distant second.
Re: Snowden leak: Cavium networking hardware may contain NSA backdoor
#459Earlier quoted context omitted.
er...what? why do you think any of that has happened? we already saw this happen in public once with Qwest: https://www.eff.org/deeplinks/2007/10/qwest-ceo-nsa-punished...
It’s happened at least three times. They got Yahoo’s CEO to [bypass SOX compliance and] hand over access to 500 million email accounts. Last I heard, she said they convinced her she wasn’t allowed to ask corporate lawyers for guidance. https://www.theguardian.com/technology/2016/oct/04/yahoo-sec... Both she and Yahoo’s shareholders suffered greatly for complying. There’s also Crypto AG, which was a foreign-owned CIA…
they apparently just happily sold themselves to German and American intelligence.
Re: Snowden leak: Cavium networking hardware may contain NSA backdoor
#460Earlier quoted context omitted.
China is way less dangerous to me than the NSA
How is the NSA personally dangerous to you?