4 ms·
> Does the same argument apply to SELinux? That the NSA can already compromise any version of the Linux kernel, or alternatively that the NSA has been fighting
by JohnStrangeII 7y ago
> Does the same argument apply to SELinux? That the NSA can already compromise any version of the Linux kernel, or alternatively that the NSA has been fighting itself since the year 2000?
Definitely. As far as I can see (public civilian sources only), the NSA's Tailored Access division can compromise any off-the-shelf PC. Or at least, given that we know that they've had the ability to install persistent viruses in the firmware of consumer hard drives 10+ years ago, it seems plausible to assume that standard PC hardware is not secure against targeted attacks.
> Does the NSA's endorsement of AES over 3DES mean that the NSA has had a backdoor in AES for decades? Does it make no sense to include actually-secure algorithms in Suite B?
Of course not. That would be a silly assumption, since we know from the Snowden revelations that the NSA is primarily targeting endpoint security. They might be able to break certain implementations of stream ciphers or maybe even have working (algebraic?) attacks against certain block ciphers - they seem to build and use a lot of ASICs, presumably not just for cryptocoin mining -, but even if these attacks exist, it would be very speculative to assume that they are used routinely.
If I wanted to break into any Linux system, I'd first create a Trojan horse and ask the administrator to kindly install it. If that didn't work, I might compromise the router and hijack the system update mechanism (maybe using stolen certificates). If that didn't work, I'd become a package maintainer or major contributor and sneak in some backdoors obfuscated as programming errors. Or I could intercept the hardware and install my own firmware on the machines. And so on and so forth. Heck, even civilian companies overtly advertise that they can break into any computer, so why should the NSA not be capable of doing it?
No need to break cryptography if endpoints are insecure.
- geofft 7y agoI can do all these things myself - compromise any standard off-the-shelf PC given physical access, add persistent viruses to the firmware of consumer hard drives given physical access, trick a sysadmin into installing something, become a package maintainer and add some backdoors, etc. So I don't think any of what you've said says anything about the NSA's capabilities, and it certainly does not let us conclude that UEFI is compromised in some way beyond being typically installed on firmware that's not hardened against physical attack (which is also true of Coreboot, traditional BIOSes, and everything else).
- _underfl0w_ 7y agoI think the parent comment was attempting to address the NSA's _willingness_ to carry out these kind of actions, not their capability to. There is documented evidence (in fact, this article mentions some known incidents) of the NSA _actually_ doing these things. That's what's different between any rogue, ethos-less malicious actor and them.