4 ms·
I think the biggest implication is how far they're willing to go to compromise commerical hardware. This could ruin Juniper, a large US company. It's insane tha
by slackingoff2017 9y ago
I think the biggest implication is how far they're willing to go to compromise commerical hardware. This could ruin Juniper, a large US company. It's insane that the government allowed them to do this.
The first thing I think of is phone basebands. If they're hacking enterprise firewalls I have to assume they've already exploited the baseband in the vast majority of phones. It's the one place they can stick a software plant over the airwaves.
I think it's time to call for open source basebands, anything else just isn't safe anymore.
- kbart 9y agoOpen source baseband only won't be enough, there are plenty of CPUs/MCUs capable of running backdoors/malware spread on any modern board (heck, even battery controller often runs on a full fledged MCU). Until we have an open hardware + software, we will never be safe from government and other well-funded crooks.
- jwfxpr 9y ago> Open source baseband only won't be enough, Not sufficient, perhaps, but necessary. A 0-day in baseband firmware seems a helluva lot more attractive a target than in a battery controller MCU.
- ethbro 9y agoExactly. Such is the entire point of a firewall. If you don't have a remotely exploitable vulnerability, it doesn't scale to global panopticon levels.
- adrianratnapala 9y agoLet not the perfect be the enemy of the good though. Every time I hear someone asking for some improvement in openness and security, someone jumps in to point out how something else will circumvent it. Fine -- but how is anything going to get done if we sit paralysed a proliferation of worries?
- wu-ikkyu 9y ago>It's insane that the government allowed them to do this. What do you mean by this? The statement seems to imply they had to ask for permission from someone other than themselves?
- scott00 9y agoI think the implication is that after the technical staff came up with the proof of concept, the operation to actually deploy it probably got reviewed by a somewhat senior official charged with making policy. He's expressing more surprise that the policy maker deemed the operation in the best interests of the United States than that the technical staff came up with the idea.
- throwasehasdwi 9y agoWhoever authorized the operation decided it was worth the many millions of damage it could do to Juniper.
- _jal 9y ago> I think the biggest implication is how far they're willing to go to compromise commerical hardware. This. Phone basebands, the Intel ME[1], NICs, Windows, anything from Cisco; they all have to be considered broken.[1] With Linux, at least there is a public code history, but considering the value of the target, tricky code can't be ruled out, nor can attacks at the distribution/packaging layer. Vernor Vinge wrote a fun book called _Deepness in the Sky_, which, among other things, explores some implications of untrustworthy computing. [1] And plenty of things not on that list, and perhaps something on it isn't. But for some risk models, they have to be assumed broken.