Live data from Hacker News

Snowden leak: Cavium networking hardware may contain NSA backdoor

twitter.com

601–610 of 628 posts

Re: Snowden leak: Cavium networking hardware may contain NSA backdoor

#601

Earlier quoted context omitted.

I have a laptop with no communications functioning and I'm sure it is not compromised. The proof of it is openly stored the wallet.dat file with no any password.

Is the idea to challenge someone to prove you wrong? Or are you suggesting that there no way for one of the aforementioned groups to recover your data remotely should they have a focused desire to recover it?

Idea is to challenge someone to propose a hardware + OS which can be as secure being online. Probably it has to be OpenBSD and the latest architecture with open BIOS.

Re: Snowden leak: Cavium networking hardware may contain NSA backdoor

#602
post #569

Earlier quoted context omitted.

So you’re saying that no matter what hardware you have, the NSA will buy that specific hardware and take the time to break it.

That's right. And I'm also saying that switching hardware will make the break attempts take longer

And in the mean time, all my browsing, payment, and location data collected by corporate ad brokers got handed over to the NSA for just the cost of a letter.

I don’t see the point in constantly changing hardware that I don’t even know is safe, just to prevent what will already happen.

Re: Snowden leak: Cavium networking hardware may contain NSA backdoor

#603

Earlier quoted context omitted.

> So, the district court reasoned, the Plaintiffs were “likely to succeed” on their claim because when the platforms moderated content, they were acting under the coercion (or significant encouragement) of government officials, in violation of the First Amendment, at the expense of both private and governmental actors. You are moving the goalposts. First it was "gov policing speech" which there was no proof of. Now i…

Reading this document, it's in extremely bad faith: > We start with coercion. On multiple occasions, the officials coerced the platforms into direct action via urgent, uncompromising demands to moderate content. Privately, the officials were not shy in their requests— they asked the platforms to remove posts “ASAP” The ASAP was in reference to a case of revenge porn, something not only against the Twitter TOS, but il…

[deleted]

Re: Snowden leak: Cavium networking hardware may contain NSA backdoor

#604

For anyone wondering "what's the big deal" it's worth remembering the NSA has a bad track record of keeping their own hacking tools secure. https://en.wikipedia.org/wiki/The_Shadow_Brokers It infuriates me the NSA actively works to undermine American security. Their brief is to protect us, not plant backdoors and then lose the keys.

>It infuriates me the NSA actively works to undermine American security. It infuriates me that the NSA actively works to undermine International security. Seriously.

I believe they do this because most critical softwares are American, and as long as the NSA has better offensive capabilities, it's better for the NSA if international defenses are low.

I don't think china or Russia really have good offensive capabilities, so as long as it is the case, this helps the US maintain some form of cyberweapon supremacy.

As long as china or small black hats don't do harm, they will not raise security standards.

Re: Snowden leak: Cavium networking hardware may contain NSA backdoor

#605

Earlier quoted context omitted.

The old men persuade the would-be suicide bomber that educating women will liberate and liberalize them, and that this is counter to the interests of those who prefer the traditional order of society. Are they even lying?

Yes, they're lying. The 'traditional order of society' is a society run by psycho pathological individuals and benefits nobody except for those individuals. But you already knew that, didn't you?

Are you saying that liberalizing the society is not counter to the interests of those who prefer traditional society?

I think it clearly is.

Re: Snowden leak: Cavium networking hardware may contain NSA backdoor

#606

Looking more closely at this, the backdoor is almost certainly based on the back-doored random number generator, Dual_EC_DRBG, which is implemented as NIST SP 800-90A. From Wiki: >>> NIST SP 800-90A ("SP" stands for "special publication") is a publication by the National Institute of Standards and Technology with the title Recommendation for Random Number Generation Using Deterministic Random Bit Generators. The publ…

Since Calvium got rewarded for being "Completely Enabling for _______ encryption chips used in VPN and Web encryption" and then lists these on its Nitrox III and Nitrox V (https://pbs.twimg.com/media/F6Y_zDQWgAAj96s?format=jpg)

AES (128/192/256 CBC, GCM)

Triple-DES (CBC, 3-key)

SHS (SHA-1/256/384/512)

HMAC (SHA-1/256/384/512)

RSA (KeyGen, SigGen and SigVer; PKCS1 V1 5; 2048bits)

ECDSA (PKG, SigGen and SigVer; P-256, P-384, P-521)

CTR DRBG (AES-256)

HASH DRBG (SHA-512)

CVL Component (IKEv2, TLS, SSH)

CKG (vendor affirmed)

Does that imply that the NSA may have kleptographic (algorithm substition, or secondary key) attacks or something different for all of these?

Re: Snowden leak: Cavium networking hardware may contain NSA backdoor

#607

Earlier quoted context omitted.

The “need” for proof here determines whether there was likely malicious intent or negligence/ignorance. People who live in an evidence-based rational world don’t skip the evidence step and go straight to possibilities and counterfactuals.

There's a certain point in the security world where paranoia becomes a requirement, even though it only breeds more paranoia. An outcome of this is the requirement to treat all possibilities as certainties, regardless of evidence. In this way, entire sections of industry will auto-assume the backdoor was both deliberate, and used both both friendlies & hostiles.

> In this way, entire sections of industry will auto-assume the backdoor was both deliberate, and used both both friendlies & hostiles.

That’s fine. But they should be equally paranoid of all substitute products/services that use other recommendations from NIST, right? Are there greater than zero products on the (US) market with no encryption in the system recommended by NIST?

Also, I don’t think I was limiting my thinking to a customer of the weak encryption product. I was also thinking through the lens of legal implications.

Re: Snowden leak: Cavium networking hardware may contain NSA backdoor

#608
post #533

Earlier quoted context omitted.

> Not really, because many of those countries you listed have mutual treaties of cooperation and are not hostile to each other. Doesn't seem to stop them from taking immensely hostile actions, e.g. the US spying on Merkel's emails, or helping killers and rapists who work for them evade arrest in "allied" countries. Governments are large and complex and have many competing interests. Why would/should one trust any of…

People/governments should trust whoever is more closely working in cooperation with their own interests over those who are working against them.

Agreed, so how do you get from that to mistrusting only China? Everyone, including China/Huawei, has an interest in growing the pie. Some entities have an interest in zero-sum competition with me and mine. That's more likely to be someone closer - Chinese companies aren't competing directly with my business, but American, Australian and Israeli ones are.

Re: Snowden leak: Cavium networking hardware may contain NSA backdoor

#609

Earlier quoted context omitted.

I see no evidence that merely being convicted of treason is enough to get you thrown in a solitary cell forever. There's a long list of plain old convicted spies[1], and they just went to regular, run of the mill prison. I would like to see the evidence that Snowden would be treated any differently. And again, I'm not saying he would've been protected as a whistleblower, just that he had to choose one or the other: t…

Regular, run of the mill prisons have solitary. It's not a special prison. Manning spent most of her time in solitary, and it's not listed in your citation.

> Manning spent most of her time in solitary, and it's not listed in your citation.

Not even remotely true.

Re: Snowden leak: Cavium networking hardware may contain NSA backdoor

#610
post #602

Earlier quoted context omitted.

That's right. And I'm also saying that switching hardware will make the break attempts take longer

And in the mean time, all my browsing, payment, and location data collected by corporate ad brokers got handed over to the NSA for just the cost of a letter. I don’t see the point in constantly changing hardware that I don’t even know is safe, just to prevent what will already happen.

You don't see the point in constantly changing hardware, but you have no problem with changing subject, I see. I would encourage you to give Zero Days a watch sometime
Post reply on HN