Live data from Hacker News

Snowden leak: Cavium networking hardware may contain NSA backdoor

twitter.com

481–490 of 628 posts

Re: Snowden leak: Cavium networking hardware may contain NSA backdoor

#481

Earlier quoted context omitted.

> did you think blowing up schools full of girls is something people genuinely believe helps their people It absolutely is something that they think helps their people, yes.

No, it's something that a bunch of old guys with issues told them helps their people. Beliefs stop when they are no longer about yourself but about how other people should live. Especially when those other people loudly protest that this is how you think they should be living. Killing them is just murder, not the spreading of ideas. But hey, those human rights are just for decoration anyway.

The old men persuade the would-be suicide bomber that educating women will liberate and liberalize them, and that this is counter to the interests of those who prefer the traditional order of society. Are they even lying?

Re: Snowden leak: Cavium networking hardware may contain NSA backdoor

#482
post #30

Earlier quoted context omitted.

Huawei stuff is proven to be compromised, just not by NSA, instead by China.

Isn't that just the US speaking in order to get more control? How is it proven? I've never seen any evidence of that, but there has been much evidence that the US does what they blames others of doing, like this and Cisco. At this point it seems the US is accusing others for doing bad things because that's what they themselves do. Huawei was growing really fast, threatening both Apple and Google. Then the US said it…

There is ample evidence of China's intentions and capability to install backdoors. Everything made in China or a heavily influenced Chinese country should be assumed to be compromised, even if 'proven' otherwise. Chances are we just haven't found the backdoor yet.

Re: Snowden leak: Cavium networking hardware may contain NSA backdoor

#483

How the NSA successfully manage to prevent the Washington Post and friends from discovering and reporting on this malicious backdoor? They've been sitting on these documents for a decade. Are the journalists just that *uncurious* about the deep contents of the documents they hold exclusive access to? Was this some kind of organizational failing?

According to Appelbaum, the person publishing these new leaks,

>Primarily these documents remain unpublished because the journalists who hold them fear they will be considered disloyal or even that they will be legally punished

Whether that's true I can't say. But as a reminder, despite constant claims that Assange is being extradited over hacking charges, something like 17 of his 18 charges are over publishing documents.

Re: Snowden leak: Cavium networking hardware may contain NSA backdoor

#484
post #471

Earlier quoted context omitted.

Is there any proof that Dual_EC_DRBG is backdoored? All I know is that Dual_EC_DRBG can be backdoored. And there are indeed suspicions, it was known from the start that not only Dual_EC_DRBG could be backdoored, but that it was rather weak to begin with. So, how could it be adopted as a standard? Now it seems that everyone takes the backdoor as a given. Is there any proof? Ideally the keys themselves (that would make…

> Is there any proof that Dual_EC_DRBG is backdoored? The algorithm is bad: it's complicated and slow. The competing algorithms were much simpler, much more secure by construction, and much faster. Most importantly, there was no obvious way to backdoor the competing algorithms, but there's a hilariously trivial way to backdoor Dual_EC_DRBG. Ergo: the only reason you would ever devise or use Dual_EC_DRBG is to introdu…

I like the link and the explanations about the weaknesses.

I detest the only evidence being circumstantial and the _argument from ignorance_ being the one that you lean on. Make the simple observations and don’t try to oversell it.

Re: Snowden leak: Cavium networking hardware may contain NSA backdoor

#485

Earlier quoted context omitted.

Wow, the deep state is so powerful that they got Nixon to say on tape that he was going to try to get the CIA to falsely use national security as an excuse to stonewall an FBI investigation. Poor innocent Nixon was no match for their telepathic powers.

Whoosh. You went clean over my head, anyway.

What's so hard to understand? Nixon was literally caught on tape[0] conspiring to cover up CREEP payments; it's a bit funny to claim Watergate was all a deep stage conspiracy to screw Nixon when he was recorded committing crimes.

[0]https://watergate.info/1972/06/23/the-smoking-gun-tape.html

Re: Snowden leak: Cavium networking hardware may contain NSA backdoor

#486
post #471

Earlier quoted context omitted.

Is there any proof that Dual_EC_DRBG is backdoored? All I know is that Dual_EC_DRBG can be backdoored. And there are indeed suspicions, it was known from the start that not only Dual_EC_DRBG could be backdoored, but that it was rather weak to begin with. So, how could it be adopted as a standard? Now it seems that everyone takes the backdoor as a given. Is there any proof? Ideally the keys themselves (that would make…

> Is there any proof that Dual_EC_DRBG is backdoored? The algorithm is bad: it's complicated and slow. The competing algorithms were much simpler, much more secure by construction, and much faster. Most importantly, there was no obvious way to backdoor the competing algorithms, but there's a hilariously trivial way to backdoor Dual_EC_DRBG. Ergo: the only reason you would ever devise or use Dual_EC_DRBG is to introdu…

Why would you need proof that it has been backdoored? The fact that it can be backdoored should be enough to disregard it for all uses right from the start.

Re: Snowden leak: Cavium networking hardware may contain NSA backdoor

#487

Earlier quoted context omitted.

> Is there any proof that Dual_EC_DRBG is backdoored? The algorithm is bad: it's complicated and slow. The competing algorithms were much simpler, much more secure by construction, and much faster. Most importantly, there was no obvious way to backdoor the competing algorithms, but there's a hilariously trivial way to backdoor Dual_EC_DRBG. Ergo: the only reason you would ever devise or use Dual_EC_DRBG is to introdu…

Why would you need proof that it has been backdoored? The fact that it can be backdoored should be enough to disregard it for all uses right from the start.

Trusting Trust says everything could be backdoored, but somehow I'm guessing you still use computers.

Re: Snowden leak: Cavium networking hardware may contain NSA backdoor

#488

Genuinely, at this point you should just assume 100% of your electronics are compromised by someone. If it’s not a government (yours or otherwise) then a corporation will fill the gaps (while in most cases also giving it to those governments) You should assume you have no privacy anywhere in your life.

If the NSA had hardware backdoors everywhere, it seems to me there would be no need for TAO or hoards of 0-days. And yet we know from the Snowden leaks that the NSA invests a lot in that stuff, correct?

Re: Snowden leak: Cavium networking hardware may contain NSA backdoor

#489
post #213
post #70

Earlier quoted context omitted.

Literally hosed. There's a funny jargon term "rubber hose cryptography" that's used to refer to the cryptanalysis method where you beat someone with a rubber hose until they give you the key. It's 100% effective against all forms of cryptography including even post-quantum algorithms.

You would be surprised that for a percent this would not work. Some even like it. Some have a deathwish and want to be a martyr. Some people blow themselves up to further a cause. Also put under heavy stress memories of keys cannot be recalled at times. It's probably slightly less effective than threatening to kill family members but probably more than threat of jail time. Either way you require someone alive and wit…

Yep... read up on interrogation resistance.

Re: Snowden leak: Cavium networking hardware may contain NSA backdoor

#490

Earlier quoted context omitted.

Why would you need proof that it has been backdoored? The fact that it can be backdoored should be enough to disregard it for all uses right from the start.

Trusting Trust says everything could be backdoored, but somehow I'm guessing you still use computers.

We use computers because it is pretty much impossible to live in modern society without using computers.

But by the time Dual_EC_DRBG was published, we already had alternatives that were better in just about every way, including being much less likely to contain a backdoor.

Post reply on HN