Live data from Hacker News

Secret Code Found in Juniper's Firewalls Shows Risk of Government Backdoors

wired.com

71–80 of 121 posts

Re: Secret Code Found in Juniper's Firewalls Shows Risk of Government Backdoors

#71
Just a quick note that 'lawnchair_larry has me dead to rights on this one.

I conceded awhile ago that Dual EC was a crypto backdoor (before BULLRUN and the antics that were uncovered with RSA and with the European standards, I had suggested, as some other crypto people had, that Dual EC was too hamfisted and obvious to be a crypto backdoor).

But I've maintained since then that virtually nobody uses Dual EC, so its impact --- while clearly malign! --- is probably limited.

Nope. ScreenOS apparently (I'm not 100% sure, but that seems to be the way the wind is blowing) uses it to key VPN connections!

FULLY CONCEDED. The immediate known practical impact of Dual EC is, if that's true, enormous.

The weird thing about this particular backdoor is that the adversary seems to have modified the Dual EC parameters. Dual EC is an RNG with an embedded public key, where an adversary with the private key can "decrypt" the random bytes it generates to recover its state and rewind/fast forward it. This backdoor appears to swap out the public key, which is something NSA has no interest in doing.

My money is that this is the work of GCHQ, the world's most unhinged signals intelligence agency, and our partners in peace.

Re: Secret Code Found in Juniper's Firewalls Shows Risk of Government Backdoors

#72
post #71

Just a quick note that 'lawnchair_larry has me dead to rights on this one. I conceded awhile ago that Dual EC was a crypto backdoor (before BULLRUN and the antics that were uncovered with RSA and with the European standards, I had suggested, as some other crypto people had, that Dual EC was too hamfisted and obvious to be a crypto backdoor). But I've maintained since then that virtually nobody uses Dual EC, so its im…

Kudos to you for the public admission. And yeah, I have to admit that when I saw this I thought of the Marshall McLuhan scene from Annie Hall with you in the role of the NYU professor.

Re: Secret Code Found in Juniper's Firewalls Shows Risk of Government Backdoors

#73
post #72
post #71

Just a quick note that 'lawnchair_larry has me dead to rights on this one. I conceded awhile ago that Dual EC was a crypto backdoor (before BULLRUN and the antics that were uncovered with RSA and with the European standards, I had suggested, as some other crypto people had, that Dual EC was too hamfisted and obvious to be a crypto backdoor). But I've maintained since then that virtually nobody uses Dual EC, so its im…

Kudos to you for the public admission. And yeah, I have to admit that when I saw this I thought of the Marshall McLuhan scene from Annie Hall with you in the role of the NYU professor.

It's pretty jaw-dropping. The news (still unconfirmed, but really looking that way) that ScreenOS keyed sessions from DualEC is probably bigger than the news that ScreenOS had an unauthorized backdoor.

Re: Secret Code Found in Juniper's Firewalls Shows Risk of Government Backdoors

#74
post #69

"I am shocked—shocked—to find that gambling is going on in here!" --from "Casablanca" I'd be shocked to learn that there are no back doors in routing equipment. Having that kind of control is just too appealing to the most powerful players -- the NSA, China, perhaps Russia. One hopes that people who care about the privacy of their communications are not relying on the routers for encryption. I would encrypt end-to-en…

I read from a reliable source I cannot immediately recall that she in fact did not post anything jihadist or even inflammatory on any social media account of hers. are you repeating a convenient falsehood or am I? in other words -- do you have a source that verified she in fact posted jihadist anything, anywhere?

Excellent point. The whole episode is very instructive.

On Sunday the New York Times quoted "law enforcement sources" as saying that she had made postings on her stream. The story got a huge amount of coverage and even came up during Tuesday's Republican debate.

On Wednesday, FBI Director Comey described the reporting as "grabled" and clarified that no, it was just private messages -- and the Times (and others) rewrote their stories to reflect it. But you can't unring a bell; most people's opinion, and even more importantly their emotional responses, are based on the original story.

Erik Wemple covers this well in the Washington Post [1]

Times' "public editor" Margeret Sullivan's looks at it as well [2], noting that two of the reporters also incorrectly reported that Hillary Clinton was the target of a criminal investigation.

[1] https://www.washingtonpost.com/blogs/erik-wemple/wp/2015/12/...

[2] http://publiceditor.blogs.nytimes.com/2015/12/18/new-york-ti...

Re: Secret Code Found in Juniper's Firewalls Shows Risk of Government Backdoors

#75
post #69

"I am shocked—shocked—to find that gambling is going on in here!" --from "Casablanca" I'd be shocked to learn that there are no back doors in routing equipment. Having that kind of control is just too appealing to the most powerful players -- the NSA, China, perhaps Russia. One hopes that people who care about the privacy of their communications are not relying on the routers for encryption. I would encrypt end-to-en…

I read from a reliable source I cannot immediately recall that she in fact did not post anything jihadist or even inflammatory on any social media account of hers. are you repeating a convenient falsehood or am I? in other words -- do you have a source that verified she in fact posted jihadist anything, anywhere?

[deleted]

Re: Secret Code Found in Juniper's Firewalls Shows Risk of Government Backdoors

#76
post #37
post #34

Earlier quoted context omitted.

Signal is open source. But you have to trust the OS it runs on...

And even if you trust the OS, you have no idea what is going on on the phone's baseband processor: https://en.m.wikipedia.org/wiki/Baseband_processor One has to assume that all are back-doored. Mobile phones are inherently not trustable. Same goes for all major firewall vendors. If you going to hack one of them as a nation state, then you're going to do all of them.

Even if you trust the OS and the baseband, you have to trust that the federated server for Signal (OpenWhisper, Cyanogen, etc) isn't storing contact discovery requests.

Re: Secret Code Found in Juniper's Firewalls Shows Risk of Government Backdoors

#78
post #38

I'll bet you ten dollars there are more backdoors, better hidden than the ones they found. Say, with Underhanded C style coding. An additional ten bucks says that Cisco and the top handful of consumer appliances also contain such backdoors. I hope the folks at Juniper are checking their toolchains, build machines and repositories for signs of similar attack. Of course, enough time has elapsed that they may need to es…

I'll bet you there are tons more unintentional vulnerabilities than actual backdoors. The state of secure software is so poor that you only need to install an actual "backdoor" if you don't have the money to throw a couple of security researchers at it for a few weeks.

Re: Secret Code Found in Juniper's Firewalls Shows Risk of Government Backdoors

#79
post #68

Juniper is using Dual EC....are you kidding me? Now I have zero doubt this is Juniper's fault because of its cooperation with NSA to keep backdoors in its systems. If I remember correctly even tptacek was claiming initially that "Dual EC is not so bad...not that many companies use it anyway, because they would be stupid to use a 1000x slower algorithm". Yeah, except some of the biggest networking equipment makers in…

If you're going to use quotation marks when referring to something I said, you should actually quote me, instead of making stuff up.

Re: Secret Code Found in Juniper's Firewalls Shows Risk of Government Backdoors

#80
post #69

"I am shocked—shocked—to find that gambling is going on in here!" --from "Casablanca" I'd be shocked to learn that there are no back doors in routing equipment. Having that kind of control is just too appealing to the most powerful players -- the NSA, China, perhaps Russia. One hopes that people who care about the privacy of their communications are not relying on the routers for encryption. I would encrypt end-to-en…

I read from a reliable source I cannot immediately recall that she in fact did not post anything jihadist or even inflammatory on any social media account of hers. are you repeating a convenient falsehood or am I? in other words -- do you have a source that verified she in fact posted jihadist anything, anywhere?

You are right. The FBI has corrected the report of her Facebook warnings that was floating around the news networks.

Marquez (the Muslim convert who sold them the guns), however, did post something on his verified Facebook account a month before the attack.[1]

And Malik (the wife) did apparently post something on Facebook minutes before the attack.

Do you disagree with my overall point, that the U.S. law enforcement has over-surveillance and under-intelligence?

1. http://www.nbcnews.com/storyline/san-bernardino-shooting/san...

Post reply on HN