Juniper breach mystery starts to clear with new details on hackers and U.S. role
1–10 of 180 posts
Re: Juniper breach mystery starts to clear with new details on hackers and U.S. role
#2Re: Juniper breach mystery starts to clear with new details on hackers and U.S. role
#3This is ground breaking. The NSA made Juniper use a backdoored algorithm, and a foreign adversary hacked into Juniper and changed the backdoor key (essentially). That's surreal.
Re: Juniper breach mystery starts to clear with new details on hackers and U.S. role
#4Already discussed a fair bit two days ago: https://news.ycombinator.com/item?id=28404219
Re: Juniper breach mystery starts to clear with new details on hackers and U.S. role
#5This is ground breaking. The NSA made Juniper use a backdoored algorithm, and a foreign adversary hacked into Juniper and changed the backdoor key (essentially). That's surreal.
This smacks way more of "well, what did you expect would happen?" than surrealism. If you introduce a vulnerability, it is nothing but hubris to think that you'll be the only one to leverage the vulnerability.
Re: Juniper breach mystery starts to clear with new details on hackers and U.S. role
#6This is a great example of why more operators should adopt white box solutions.
Re: Juniper breach mystery starts to clear with new details on hackers and U.S. role
#7How many more back-doors like that are out there that are not in public domain yet?
And can we trust standard committees who, funded by public, put back doors in encryption and weaken security of public services?
Re: Juniper breach mystery starts to clear with new details on hackers and U.S. role
#8This is a great example of why more operators should adopt white box solutions.
Open- and FreeBSD deserve more usage
Re: Juniper breach mystery starts to clear with new details on hackers and U.S. role
#9Re: Juniper breach mystery starts to clear with new details on hackers and U.S. role
#10We are playing with a slippery slope! A backdoor is a backdoor. Honestly it is getting to the point where open source is the only way to go - imo.
I'd like to be able to perform SAST scans and code review on all software that protects my enclaves.