3 ms·
Seems like a prime opportunity for a class action lawsuit. Juniper was selling a class of products that categorically did not do what it claimed. What would be
by oroup 11y ago
Seems like a prime opportunity for a class action lawsuit. Juniper was selling a class of products that categorically did not do what it claimed. What would be interesting is their method of defense. As was pointed out to me in an earlier thread, companies have legal immunity when assuring the intelligence community with their work.[1] But Juniper already claims that they do not assist third parties to compromise their products. So they would either need to change their statements or be ineligible for this defense.
- superuser2 11y agoThere is no indication that Juniper cooperated with the NSA or acted intentionally to compromise its products. All software has defects, and if bugs entitled customers to civil damages there would be 0 technology companies left alive. The standard is negligence, but the NSA is sophisticated enough to compromise designs that were not negligent.
- chei0aiV 11y agohttp://blog.cryptographyengineering.com/2015/12/on-juniper-backdoor.html http://blog.cryptographyengineering.com/2015/12/on-juniper-b...
- phicoh 11y agoIt seems to me that having Dual_EC_DRBG in your code today is an extreme case of incompetence. Ideally, that should be enough to sue them out of business.