Live data from Hacker News

Juniper breach mystery starts to clear with new details on hackers and U.S. role

bloomberg.com

81–90 of 180 posts

Re: Juniper breach mystery starts to clear with new details on hackers and U.S. role

#81
post #14
post #10

We are playing with a slippery slope! A backdoor is a backdoor. Honestly it is getting to the point where open source is the only way to go - imo. I'd like to be able to perform SAST scans and code review on all software that protects my enclaves.

Most open source crypto code just does what NIST and DJB say to do. There's no magic imparted by it being FOSS.

On the contrary, there's plenty of different implementations of the same algorithms.

Plus it's also extremely difficult to make underhanded changes to magic numbers if the source code is public.

Re: Juniper breach mystery starts to clear with new details on hackers and U.S. role

#82
post #77
post #44

> Members of a hacking group linked to the Chinese government called APT 5 hijacked the NSA algorithm Just wanted to acknowledge how brilliant that is. They could have made any other code change, but it was genius using NSA's own backdoor. NSA advocated for that backdoor to be included in the standards. The US government then would be embarrassed and would want to cover up any issues related to it, including the fact…

There were two backdoors that were discovered at the time btw, the other one was a hardcoded password that could get you in any router (or something like that?) Odds are that there are more that weren't caught.

Correct. Same as Fortinet: https://betanews.com/2016/01/12/fortinet-firewalls-feature-h...

Re: Juniper breach mystery starts to clear with new details on hackers and U.S. role

#83

Earlier quoted context omitted.

Kind of, but my reading of it is that it was also a supply-side chain attack where they modified the constant that was used in the code before the binary was built. So at that level of access, I'm not sure any algorithms would hold up. I don't think Dual ECDRGB was used to attack the source control system.

The brilliant part is that they did it in a way that remained undetected for so long. And the reason they could do that is because the backdoor already existed.

I wonder how much Intellectual Property was exfiltrated because of this?

Re: Juniper breach mystery starts to clear with new details on hackers and U.S. role

#84
post #44

> Members of a hacking group linked to the Chinese government called APT 5 hijacked the NSA algorithm Just wanted to acknowledge how brilliant that is. They could have made any other code change, but it was genius using NSA's own backdoor. NSA advocated for that backdoor to be included in the standards. The US government then would be embarrassed and would want to cover up any issues related to it, including the fact…

Probably pretty chill internally. "The thing we knew would happen and that every expert said would happen happened."

"It fell within the acceptable matrix risk parameters."

Re: Juniper breach mystery starts to clear with new details on hackers and U.S. role

#85
post #3

This is ground breaking. The NSA made Juniper use a backdoored algorithm, and a foreign adversary hacked into Juniper and changed the backdoor key (essentially). That's surreal.

lol no! it was totally expected and security people and encryption advocates have been literally saying this kind of thing was bound to happen for Decades. You can only imagine how much of this remains out there. Also, see the recent Apple debacle. Letting government interfere with private business without a warrant is always, always bad. Even with a warrant it is troubling, but at least there are some checks and balances from the courts (supposedly neutral party)

Re: Juniper breach mystery starts to clear with new details on hackers and U.S. role

#86
post #3

This is ground breaking. The NSA made Juniper use a backdoored algorithm, and a foreign adversary hacked into Juniper and changed the backdoor key (essentially). That's surreal.

> The NSA made Juniper use a backdoored algorithm It's very important to clarify that the NSA didn't make them use it. The DoD required it as terms for future contracts. Juniper grabbed the money in knowing exchange for putting their customers at risk. Why does that distinction matter? It dramatically increases Juniper's culpability in the scheme. If the DoD had actually forced them to use it, that dramatically reduc…

Exactly, if a company is willing to go to court they can't be made to build backdoors like this, at least not yet. Hence why everyone was peeved at apple for siding with the government to add government spyware to every apple phone to make sure citizens comply.

Re: Juniper breach mystery starts to clear with new details on hackers and U.S. role

#87
post #42
post #3

This is ground breaking. The NSA made Juniper use a backdoored algorithm, and a foreign adversary hacked into Juniper and changed the backdoor key (essentially). That's surreal.

It's Bloomberg. Be skeptical.

But be far less skeptical than if it had come out of a Rupert Murdoch owned news source.

Re: Juniper breach mystery starts to clear with new details on hackers and U.S. role

#88
post #3

This is ground breaking. The NSA made Juniper use a backdoored algorithm, and a foreign adversary hacked into Juniper and changed the backdoor key (essentially). That's surreal.

Not surreal at all. It's exactly what everyone in the cryptography communuty said would happen if people listened to the government and added backdoors for the "good guys". Hope this sort of thing keeps happening. I want more concrete examples to cite when people defend this stupidity. I want the governments of the world to be too embarrassed to talk about cryptography ever again, least of all demand backdoors into p…

They won't. You'll have lists and lists and lists, and they'll just say "you live in a society, you have no reasonable expectation of privacy", and then expect you replace your walls with glass on your house.

They're too far gone if they still believe "if you have nothing to hide, you have nothing to fear" so openly.

Re: Juniper breach mystery starts to clear with new details on hackers and U.S. role

#89

Earlier quoted context omitted.

You are correct, and the transition point was 9/11. Before that the NSA was doing good work shoring up our digital infrastructure, as well as working with the FBI to go after international crime syndicates. I wish we could get back to that.

Not at all, it was focused on implementing backdoors and surveillance for decades before that.

[deleted]

Re: Juniper breach mystery starts to clear with new details on hackers and U.S. role

#90

For its first 50 years or so NSA had a dual mission: protect the US from spying while spying on others. But these last 20 years they've undermined that first mission. They've now attacked and weakened American technology so many times that you'd be crazy to trust anything the NSA offers to make you more secure. It doesn't help when they lose control of their own hacking tools igniting a major expansion in ransomware.…

"You either die a hero, or live long enough to see yourself become the villain." -Harvey Dent
Post reply on HN