Live data from Hacker News

Juniper breach mystery starts to clear with new details on hackers and U.S. role

bloomberg.com

51–60 of 180 posts

Re: Juniper breach mystery starts to clear with new details on hackers and U.S. role

#52

Bloomberg at the frontline of "having no idea how anything works at all". When the NSA designed DEC, they primed it with constants, that you'd need to know to break the encryption with low effort. Somebody discovered that and made it known publicly. So now before the rumors evolve into actual security engineers looking into it, the NSA creates a scapegoat APT, that "altered" some "code" at Juniper. Of course nobody f…

I lost you at the second paragraph. Crypto researches generally agree today that the NSA actually chose strong contents for DES (I assume that's what you meant by DEC?). They invented differential cryptanalysis a decade before anyone else, and used that to strengthen the cypher. Everyone suspected their motives at the time, but eventually academy caught up with the knowledge the NSA had, and could show that the constants are in fact good.

Too bad they're doing the opposite of that nowadays...

Re: Juniper breach mystery starts to clear with new details on hackers and U.S. role

#54
post #44

> Members of a hacking group linked to the Chinese government called APT 5 hijacked the NSA algorithm Just wanted to acknowledge how brilliant that is. They could have made any other code change, but it was genius using NSA's own backdoor. NSA advocated for that backdoor to be included in the standards. The US government then would be embarrassed and would want to cover up any issues related to it, including the fact…

Probably pretty chill internally. "The thing we knew would happen and that every expert said would happen happened."

Re: Juniper breach mystery starts to clear with new details on hackers and U.S. role

#55
post #52

Bloomberg at the frontline of "having no idea how anything works at all". When the NSA designed DEC, they primed it with constants, that you'd need to know to break the encryption with low effort. Somebody discovered that and made it known publicly. So now before the rumors evolve into actual security engineers looking into it, the NSA creates a scapegoat APT, that "altered" some "code" at Juniper. Of course nobody f…

I lost you at the second paragraph. Crypto researches generally agree today that the NSA actually chose strong contents for DES (I assume that's what you meant by DEC?). They invented differential cryptanalysis a decade before anyone else, and used that to strengthen the cypher. Everyone suspected their motives at the time, but eventually academy caught up with the knowledge the NSA had, and could show that the const…

The GP is talking about Dual EC (the infamous algorithm in question) and abbreviating it DEC.

Re: Juniper breach mystery starts to clear with new details on hackers and U.S. role

#56
post #3

This is ground breaking. The NSA made Juniper use a backdoored algorithm, and a foreign adversary hacked into Juniper and changed the backdoor key (essentially). That's surreal.

Not surreal at all. It's exactly what everyone in the cryptography communuty said would happen if people listened to the government and added backdoors for the "good guys".

Hope this sort of thing keeps happening. I want more concrete examples to cite when people defend this stupidity. I want the governments of the world to be too embarrassed to talk about cryptography ever again, least of all demand backdoors into private infrastructure.

Re: Juniper breach mystery starts to clear with new details on hackers and U.S. role

#58
post #23
post #3

This is ground breaking. The NSA made Juniper use a backdoored algorithm, and a foreign adversary hacked into Juniper and changed the backdoor key (essentially). That's surreal.

Is there a list of exactly what equipment (model numbers) was breached?

https://setkorp.com

Re: Juniper breach mystery starts to clear with new details on hackers and U.S. role

#59
post #35
post #32

Earlier quoted context omitted.

Right, I'm wondering what models were designed to officially run the software that was infected, and if there are models that are known (by source code, reverse engineering or otherwise) to run uninfected firmware.

Basically any Juniper NetScreen (SSG-xxx) device, since it was ScreenOS that was modified by the attackers.

https://setkorp.com

Re: Juniper breach mystery starts to clear with new details on hackers and U.S. role

#60
post #3

This is ground breaking. The NSA made Juniper use a backdoored algorithm, and a foreign adversary hacked into Juniper and changed the backdoor key (essentially). That's surreal.

This needs to be brought up every single time congress proposes encryption backdoors.
Post reply on HN