Earlier quoted context omitted.
Why would you need proof that it has been backdoored? The fact that it can be backdoored should be enough to disregard it for all uses right from the start.
Trusting Trust says everything could be backdoored, but somehow I'm guessing you still use computers.
Snowden leak: Cavium networking hardware may contain NSA backdoor
501–510 of 628 posts
Re: Snowden leak: Cavium networking hardware may contain NSA backdoor
#502Earlier quoted context omitted.
If your threat model includes the nation state where you physical infrastructure is, you're hosed.
Literally hosed. There's a funny jargon term "rubber hose cryptography" that's used to refer to the cryptanalysis method where you beat someone with a rubber hose until they give you the key. It's 100% effective against all forms of cryptography including even post-quantum algorithms.
Re: Snowden leak: Cavium networking hardware may contain NSA backdoor
#503Earlier quoted context omitted.
None of these are EUropean countries.
Scroll down and learn about FVEY+3 and friends.
Re: Snowden leak: Cavium networking hardware may contain NSA backdoor
#504Earlier quoted context omitted.
Trusting Trust says everything could be backdoored, but somehow I'm guessing you still use computers.
If, for example, SHA2 had a backdoor or a weakness known only to the NSA, then random contractors (like Snowden) could use that to extract money from the Bitcoin network, which uses SHA256 as its core cryptographic primitive. That's easily a billion dollar motivation right there, and I can't imagine a bunch of low-paid government drones resisting that cash prize. Everyone has a price. Hence, there's a level of trust…
Of the people I know that work with highly privileged materials, none would take advantage or abuse something like this, even with such a high payout. Even if they did, how would they continue to live comfortably? That said, it just takes one person under the right circumstances to act maliciously, which is why screening and compartmentalization is critically important for these organizations.
Re: Snowden leak: Cavium networking hardware may contain NSA backdoor
#505Earlier quoted context omitted.
Nothing? I mean, you are already in US-based cloud, so if NSA is interested, they will just request information directly, no backdoors needed. (This is a good test for your security team, btw: if they say anything other that "we do nothing", you know its all security theater)
Very good point. That was the consensus from our team, so I think we're okay. Ironically, the data we're securing is because of US government requirements. So if the government wants to spy on itself, who are we to say?
Re: Snowden leak: Cavium networking hardware may contain NSA backdoor
#506Earlier quoted context omitted.
Huawei stuff is proven to be compromised, just not by NSA, instead by China.
To my knowledge, no proof has actually been publicly presented for this claim. There have been a few stories that didn't pan out (like the one that boiled down to, "Huawei devices have telnet installed"), but no actual evidence of backdoors has come to light yet. This is despite the fact that Huawei has been under an extraordinary level of scrutiny for years. British intelligence was given extensive access to Huawei'…
Re: Snowden leak: Cavium networking hardware may contain NSA backdoor
#507Earlier quoted context omitted.
[flagged]
I'd usually agree, except when it comes to saying anything critical of China on the Internet, my statement is very true. The wumao is a real thing, and they're pervasive within online tech.
Wumaos are low-paid grunts and sincere idiots who disingenuously downvote, report and post irrelevant nonsense regarding racist imperialist AmeriKKKa or legitimate Chinese clay/territorial waters/6000 years of peaceful history. This is very easy to see. You're free to suspect any interlocutor as being one, of course, but if that's your only retort, you'd do better not stooping to the level of an undeniable propagandist and instead conceding the object-level issue – or keeping silent.
Re: Snowden leak: Cavium networking hardware may contain NSA backdoor
#508Earlier quoted context omitted.
Youtube would delist that before they could all see it though.
You know there are other ways to have a video and send it to people than YouTube, right? You can just email a link from dropbox or gdrive, or an attachment, or send a WhatsApp/Telegram/etc. message, send a letter with a USB drive, etc.
Why do you think governments are demanding those services give them access to quickly remove "misinformation"?
Re: Snowden leak: Cavium networking hardware may contain NSA backdoor
#509Earlier quoted context omitted.
Isn't that just the US speaking in order to get more control? How is it proven? I've never seen any evidence of that, but there has been much evidence that the US does what they blames others of doing, like this and Cisco. At this point it seems the US is accusing others for doing bad things because that's what they themselves do. Huawei was growing really fast, threatening both Apple and Google. Then the US said it…
There is ample evidence of China's intentions and capability to install backdoors. Everything made in China or a heavily influenced Chinese country should be assumed to be compromised, even if 'proven' otherwise. Chances are we just haven't found the backdoor yet.
Re: Snowden leak: Cavium networking hardware may contain NSA backdoor
#510Earlier quoted context omitted.
That doesn't prove anything. You're just saying that Huawei could theoretically be compromised, but the above commenter asked for evidence.
They are compromised in terms of governance, and their legal environment is the proof of this. Nobody has ever claimed that Huawei devices have backdoors. The issue is that the supply chain is compromised by legal means, not the hardware or software currently being shipped has technical vulnerabilities.
I'd love it if people actually stuck to some principles and stopped buying from any of these countries. But using that legal situation as a reason to single out China/Huawei is bullshit.