Live data from Hacker News

Juniper breach mystery starts to clear with new details on hackers and U.S. role

bloomberg.com

91–100 of 180 posts

Re: Juniper breach mystery starts to clear with new details on hackers and U.S. role

#91
post #44

> Members of a hacking group linked to the Chinese government called APT 5 hijacked the NSA algorithm Just wanted to acknowledge how brilliant that is. They could have made any other code change, but it was genius using NSA's own backdoor. NSA advocated for that backdoor to be included in the standards. The US government then would be embarrassed and would want to cover up any issues related to it, including the fact…

> The US government then would be embarrassed and would want to cover up any issues related to it, including the fact that it was taken over by someone else!

I feel more like, there’s a chance that by modifying an intentional backdoor it could be that it would go unnoticed because anyone at the NSA looking at it may skip over reviewing closely the part of the code that has the known backdoor in it.

Re: Juniper breach mystery starts to clear with new details on hackers and U.S. role

#92
post #72

For its first 50 years or so NSA had a dual mission: protect the US from spying while spying on others. But these last 20 years they've undermined that first mission. They've now attacked and weakened American technology so many times that you'd be crazy to trust anything the NSA offers to make you more secure. It doesn't help when they lose control of their own hacking tools igniting a major expansion in ransomware.…

> you'd be crazy to trust anything the NSA offers to make you more secure You'd also be crazy to trust anything made by American gear vendors. This is not the only instance of this, just one of the ones for which FVEY got caught. Is non-US gear also compromised? Yeah, probably. But the PLA and the GRU can't physically confine you to an 8x8 steel cage on trumped-up charges predicated on the data they exfil from your n…

Would you be safe by running multiple layers around your network? Each layer from a different vendor?

Re: Juniper breach mystery starts to clear with new details on hackers and U.S. role

#93
post #42

Earlier quoted context omitted.

It's Bloomberg. Be skeptical.

I'm surprised we haven't seen an article explaining that the chip shortage is due to so many hidden chips being secretly placed on mobos used by the largest vendors.

Why is that story so far fetched exactly?

Re: Juniper breach mystery starts to clear with new details on hackers and U.S. role

#94
post #11
post #6

This is a great example of why more operators should adopt white box solutions.

It would be interesting to see a refreshed view of what products white-box is able to replace. I recall that Juniper and Cisco were hard to replace for some products because the performance edge was in proprietary ASICs that aren't available to white box builders. I suspect that CPU improvements and things like user-space networking (DPDK and friends) might have closed the gap some, but I haven't seen any recent anal…

Actually I think P4 programmable switch ASICs such as Barefoot are going to become more prevalent over time and hence features will be available in software.

Re: Juniper breach mystery starts to clear with new details on hackers and U.S. role

#95
post #11

Earlier quoted context omitted.

It would be interesting to see a refreshed view of what products white-box is able to replace. I recall that Juniper and Cisco were hard to replace for some products because the performance edge was in proprietary ASICs that aren't available to white box builders. I suspect that CPU improvements and things like user-space networking (DPDK and friends) might have closed the gap some, but I haven't seen any recent anal…

Actually I think P4 programmable switch ASICs such as Barefoot are going to become more prevalent over time and hence features will be available in software.

hasn't P4 been kind of dead in the water for the last couple of years.

Re: Juniper breach mystery starts to clear with new details on hackers and U.S. role

#96
post #64

Earlier quoted context omitted.

Well, JunOS is FreeBSD -- the magic is in their proprietary hardware. I'm not aware of open/whitebox solutions that can compete

Yes and no TBH. Some Juniper gear emulated the IP2 forwarding asics in software, its fairly decent for what it is. All of the packet inspection stuff runs inside of FreeBSD. The new vSRX is all software and uses commodity cpu power for everything. For raw speed, pfsense does a really good job on the low end of things but doesn't offer a lot of the inspection/IPS features that JunOS has. Arguably few people actually n…

The same goes for a VMX, which arguable is even harder to virtualize (and it is not on par with a real MX series router yet). Mainly because emulating some trio chipset features is at the moment very hard/impossible to do with great performance. (especially the dense queing part)

Re: Juniper breach mystery starts to clear with new details on hackers and U.S. role

#97
post #44

> Members of a hacking group linked to the Chinese government called APT 5 hijacked the NSA algorithm Just wanted to acknowledge how brilliant that is. They could have made any other code change, but it was genius using NSA's own backdoor. NSA advocated for that backdoor to be included in the standards. The US government then would be embarrassed and would want to cover up any issues related to it, including the fact…

When an Agency with the purpose of ensuring the Security of the Nation does the exact opposite... makes you wonder why they even exist.

Re: Juniper breach mystery starts to clear with new details on hackers and U.S. role

#98

Earlier quoted context omitted.

I'm surprised we haven't seen an article explaining that the chip shortage is due to so many hidden chips being secretly placed on mobos used by the largest vendors.

Why is that story so far fetched exactly?

That so many hidden/secret chips are being placed on mobos that we are suffering a global chip shortage because of it?

Do you really need it explained why that's far fetched? I'm going to let you think on that a bit longer. It should have kicked in by now.

Re: Juniper breach mystery starts to clear with new details on hackers and U.S. role

#99
post #14
post #10

We are playing with a slippery slope! A backdoor is a backdoor. Honestly it is getting to the point where open source is the only way to go - imo. I'd like to be able to perform SAST scans and code review on all software that protects my enclaves.

Most open source crypto code just does what NIST and DJB say to do. There's no magic imparted by it being FOSS.

NIST or DJB. It's safer to ignore NIST and do what DJB says.

Re: Juniper breach mystery starts to clear with new details on hackers and U.S. role

#100
Are there alternative OSes for this very specific hardware? I mean, Juniper aside, the risk that other network gear is similarly affected as well surely is not zero, so I wonder if there is any FOSS (also as in auditable) alternative firmware for these devices, or any ongoing efforts to create one.
Post reply on HN