Live data from Hacker News

Snowden leak: Cavium networking hardware may contain NSA backdoor

twitter.com

81–90 of 628 posts

Re: Snowden leak: Cavium networking hardware may contain NSA backdoor

#81
post #21

How the NSA successfully manage to prevent the Washington Post and friends from discovering and reporting on this malicious backdoor? They've been sitting on these documents for a decade. Are the journalists just that *uncurious* about the deep contents of the documents they hold exclusive access to? Was this some kind of organizational failing?

mainstream journalists are incredibly unreliable. it's absolutely clear to everyone that you cannot trust nyt and similar publications. i never read them anyway, and when I do come across articles on topics I'm knowledgeable about, i'm appalled by how wrong they are.

Modern journalists are just terminally online twitter heads.

"Why go out or talk to anyone when I can just stay home and be on twitter all day!?!"

It's the absolute worst outcome for journalism, and none of publications seem to care. If I had a publication the first thing I would do is ban twitter use (and probably go bankrupt because of it.)

Re: Snowden leak: Cavium networking hardware may contain NSA backdoor

#82
post #56

Earlier quoted context omitted.

Law firms aren't terribly entrepreneurial. Absent somebody paying them their hourly rate, I suspect not a single document would be read. Newspapers regularly take risks deploying humans to investigate issues without any assurance there will be a story at the bottom, but even the newspaper business has less appetite for that these days (as an aside, I suspect it's that margin that the financial investors have exploite…

>Law firms aren't terribly entrepreneurial. Personal injury guys are the most entrepreneurial people I know...

That's why other lawyers call them ambulance chasers. Their ethics are notoriously questionable.

Re: Snowden leak: Cavium networking hardware may contain NSA backdoor

#83

How the NSA successfully manage to prevent the Washington Post and friends from discovering and reporting on this malicious backdoor? They've been sitting on these documents for a decade. Are the journalists just that *uncurious* about the deep contents of the documents they hold exclusive access to? Was this some kind of organizational failing?

> Was this some kind of organizational failing?

No...the organization is behaving exactly as intended.

Re: Snowden leak: Cavium networking hardware may contain NSA backdoor

#84
post #51

Ok the claim is the CPU was compromised and they were using ARM based tech. Is then ARM compromised? Cavium is now Marvell Technology.

ARM just licenses the ISA and provides some reference designs. Individual manufacturers can (and often do) add their own extensions and design the actual chips.

Re: Snowden leak: Cavium networking hardware may contain NSA backdoor

#86
post #45

Earlier quoted context omitted.

I think at this point it's pretty safe to assume that all of the well-known network hardware is compromised.

I wonder if MikroTik would be compromised- they’re Latvian and don’t necessarily have to bow to the NSA.

MikroTik has come up in their slides before, yes...

Re: Snowden leak: Cavium networking hardware may contain NSA backdoor

#88
post #6

The tweet seems to imply that the entire Ubiquiti Networks line of network hardware could be compromised. That's a shame; I was thinking of installing some in my house. I'm sure that Ubiquiti's customers will not be happy if they find out that the US Govt can access their private data.

I'm currently replacing my network equipment with Mikrotik, not because I believe it to be safer than Ubiquity, but because then at least it's made in the EU.

But now I'm thinking: Is it better that the US is spying on me in Europe, vs. having EU governments do it? I feel like I'd be somewhat more safe from the US, compared to if my own government decides to spy on me. Maybe I should look into Chilean network equipment, I can't imaging that they'd have much interest in my online activities.

Re: Snowden leak: Cavium networking hardware may contain NSA backdoor

#89

Looking more closely at this, the backdoor is almost certainly based on the back-doored random number generator, Dual_EC_DRBG, which is implemented as NIST SP 800-90A. From Wiki: >>> NIST SP 800-90A ("SP" stands for "special publication") is a publication by the National Institute of Standards and Technology with the title Recommendation for Random Number Generation Using Deterministic Random Bit Generators. The publ…

That's a very specific module - one of Cavium's dozens and dozens of products.

Hard to tell what it is, more information is needed.

Re: Snowden leak: Cavium networking hardware may contain NSA backdoor

#90
post #70
post #65

Earlier quoted context omitted.

If your threat model includes the nation state where you physical infrastructure is, you're hosed.

Literally hosed. There's a funny jargon term "rubber hose cryptography" that's used to refer to the cryptanalysis method where you beat someone with a rubber hose until they give you the key. It's 100% effective against all forms of cryptography including even post-quantum algorithms.

That's actually not true. It can do nothing about M of N cryptography. (That's when a key is broken up such that there are N parts, and at least M (less than N) are required to decrypt. It doesn't matter how many rubber hoses you have, one person can fully divulge or give access to their key and it's still safe.
Post reply on HN