24 ms·
Spy agency ducks questions about 'back doors' in tech products
- ChuckNorris89 6y agoIs anyone actually surprised of a "we can neither confirm nor deny" type of answer coming from intelligence agencies?
- matthewdgreen 6y agoYes. After the Snowden leaks and Shadowbrokers/Vault7/WannaCry disasters, the agencies put a lot of effort into reassuring the public that US technology was trustworthy. This included things like making public the Vulnerabilities Equities Process [1], and other work to restore trust in cryptographic standards agencies like NIST [2]. It also included more public engagement with industry to report serious vulnerabilities [3]. The intelligence community didn't open up like this because they wanted to be nice. They did it because there was a very real concern that US industry would be damaged in the eyes of global consumers -- primarily as a result of our intelligence agencies being being too aggressive and, frankly, being sloppy. (It's bad enough to pay for and hoard backdoors, it's another thing entirely when those backdoors are repeatedly stolen and leaked for bad actors to use.) I guess the news here is that the NSA didn't learn very much from these episodes, or at least, it no longer feels like it needs to repair the damage. [1] https://en.wikipedia.org/wiki/Vulnerabilities_Equities_Process https://en.wikipedia.org/wiki/Vulnerabilities_Equities_Proce... [2] https://www.nist.gov/system/files/documents/2017/05/09/VCAT-Report-on-NIST-Cryptographic-Standards-and-Guidelines-Process.pdf https://www.nist.gov/system/files/documents/2017/05/09/VCAT-... [3] https://www.thesslstore.com/blog/nsa-microsoft-releases-patch-to-fix-latest-windows-10-vulnerability/ https://www.thesslstore.com/blog/nsa-microsoft-releases-patc...
- dmurray 6y agoCouldn't they just have said "no we have no backdoors"? NSA would look good, Congress would look good for asking the tough questions. When eventually new evidence comes to light that they do have backdoors, they have the choice then between continuing to deny deny deny, or pointing to national security interests.
- ChuckNorris89 6y ago>Couldn't they just have said "no we have no backdoors"? No, because once their backdoors are (inevitably) going to be found/leaked, they'll come off as liars. Plus, if they would have said no, nobody would buy that or would think they're asleep at the wheel.
- kube-system 6y agoLying to Congress is also a crime, publishable by prison time.
- nerdponx 6y agoI guess the news here is that the NSA didn't learn very much from these episodes, or at least, it no longer feels like it needs to repair the damage. This seems to be a common thread in American political corruption. After a certain point, the public just doesn't remember or can't be bothered to care or feels powerless to do anything. Then you can basically do whatever you want as long as you stay quiet enough to avoid another wave of media outrage.
- atty 6y agoI can’t tell from this - is Wyden also against back doors for the purpose of FBI/law enforcement use?
- boomboomsubban 6y agoQuote from Wyden in the article >Secret encryption back doors are a threat to national security and the safety of our families – it’s only a matter of time before foreign hackers or criminals exploit them in ways that undermine American national security
- pulse7 6y agoIn other words: NSA paved the way for foreign hackers and criminals...
- duxup 6y agoIt's certainly possible, but I suspect just traditional bugs and poor software is more likely the cause for such events. Software / hardware industry is PLENTY good at paving the way all on its own.
- boomboomsubban 6y agoThe article presents an example where we basically know that it happened with Juniper Networks. As you say, the hardware/software industries have enough difficulties with security acting on their own. They don't need the NSA purposely making more holes.
- pulse7 6y agoMaybe they "need" many such "holes" (which are treated as "bugs") just to make sure that if they disable some of those "holes" (because hackers/public found it out) whey still have others ready for the same purpose...
- bitxbitxbitcoin 6y ago
- lki876 6y agoOh come on, any answer but 'no' is yes. Also 'no' is yes.
- pulse7 6y ago"The tactics drew widespread attention starting in 2013, when Snowden leaked documents referencing these practices." So this is what Snowden has done: he "drew widespread attention to these tactics". Before Snowden they would call you "paranoid" if you would allow yourself to mention it. Today they can not call you paranoid anymore. And yes, it has hurt US industry reputation. Many don't trust Intel processors and Cisco routers anymore (among other products). They actually destroyed computers and internet as we knew them in the 1990'ies. It is not fun anymore to own a computer or a phone if you know that NSA can get access to it anytime they want... and you will never know if they accessed it...
- warent 6y agoIt has always been true that any computer connected to the internet could be accessed by an unauthorized party, even before the leaks. Disconnect from the internet and nobody is getting in, including the NSA.
- deleted 6y ago[deleted]
- redbeard0x0a 6y agoa little interdiction while that new airgapped laptop is shipped to you and they got you, even though you never connected to a network
- derefr 6y agoExactly what have they got, if you never connect it to a network afterward, either? A key-log that never makes it back to them? (I’m presuming here that the laptop is openable, and that you will do so and physically remove any wi-fi M.2 card from it — and associated antennae — since you won’t be using it. There might be some sort of extra surface-mount snooper chip left onboard that could replicate the same function — but without big antennas, how’s it going to report?)
- 6y ago
- remote_phone 6y agoI have a friend that works for a chip company and he said he couldn’t get into details but the amount of back doors in communication companies and in chips would scare the shit out of me.
- pjc50 6y agoCounterpoint: I actually do work at a chip company and have never heard of any of this internally. Even from the people working on secure biometrics. Neither of these anecdotes proves anything.
- dylan604 6y agoThe first rule of fight club is you do not talk about fight club. If a chip company was placing back doors into their products, I doubt it would be something they would talk about around the water cooler. However, if a back door was implemented on this level, if some one broke rule #1 and rule #2 of fight club, then I don't see how it would be able to be kept quite after that.
- duxup 6y agoSo we only believe people who claim something is happening with no proof ... because anyone who doesn't see it happening just isn't in the special circle of folks doing it?
- dylan604 6y agowhat are you on about? if nobody in the know talks, how does anyone find out about it? if people are talking about it, then anyone with any know-how will start to investigate. if you choose to believe something someone tells you with no proof, then that's on you. claiming we do the same thing is a broad brush that i'm not getting painted on by thank you very much
- duxup 6y agoI don't understand what you're saying. We had one anecdote saying a thing is happening, the second from someone who says it isn't. Your post seemed to indicate that the second post isn't true because maybe that person just doesn't know about it. That seems to refute the second and assume the first is true.
- boomboomsubban 6y ago>Three former senior intelligence agency figures told Reuters that the NSA now requires that before a back door is sought, the agency must weigh the potential fallout and arrange for some kind of warning if the back door gets discovered and manipulated by adversaries. Meaning that before, they were free to plant as many back doors as they pleased without any concern for the consequences. And even now, they just need to think about it a bit and warn somebody, no idea who they tell, if they notice it being used. >NSA now asserts that it cannot locate this document This is fairly clear proof of either corruption or complete incompetence.
- duxup 6y ago"Meaning that before, they were free to plant as many back doors as they pleased without any concern for the consequences." Kinda. There apparently is some approval process and such but I'm not sure everyone at he agency was able to make such requests in the first place... I'm with your gist, I'm just not sure we know how widespread it really was. I'm not inclined to agree that it must have been ultra widespread.
- boomboomsubban 6y agoWe know that just one of the NSA's related programs, Bullrun, had a budget of $250 million a year from 2011. And by their own admission this gave them access to "vast amounts of encrypted Internet data which have up till now been discarded are now exploitable". Further, their reports mention much more activity that Snowden did not have clearance for. We don't know the full extent of their activities, but it clearly far surpassed what should be tolerable.
- appleflaxen 6y agoand it's not consideration of how many rights are violated; it's a consideration of the PR fallout. The NSA needs to be disbanded.
- orangepanda 6y agoY'all reading into it too much. They're under no obligation to tell the truth. Might as well said "there's no backdoors" but that's not a PR happy answer.
- pbhjpbhj 6y agoDoesn't having a Congress that can't demand the truth by force of law (ie create an obligation; they of course won't necessarily get the truth) mean that you're no longer a democracy. I mean starkly that's an indication that rule of law no longer stands.
- jdndbfbf 6y agoThe director of the NSA lied while under oath to congress, and nothing happened. As far as I'm concerned, what 3 letter agencies say publically is irrelevant.
- dylan604 6y agoTo be fair, Clapper did come back for a follow up, and basically said, "oops, looks like I was wrong." That's it. Congress didn't push back, and thanked him for his service. So looks like Congress is complicit as well.
- sonotathrowaway 6y agoClapper was forced to issue a retraction after Snowden leaked material showing he perjured himself. He defended his then answer as the “least untruthful answer” he could give, maybe that’s a term of art in intelligence when you intentionally suborn oversight.
- Liquix 6y agoIt's an interesting case of cognitive dissonance. Most will admit when pressed a bit that the CIA/NSA/FBI do not have our best interests at heart and are out of control. They have repeatedly lied under oath, lied to congress, lied to the public, run human experiments on unwitting citizens, collect data on all of us, etc with complete impunity. However many people somehow simultaneously hold the belief that these agencies should continue to exist, are deserving of our taxpayer dollars, and are generally Good Guys who happen to do bad things sometimes. Perhaps it's just too exhausting to consider the extent of corruption in the USA.
- bulletsvshumans 6y agoI think it's clear that they are out of control, from the examples you list among others. The harder argument is that they're not doing it in our best interest. Without good visibility into their activities (which could very well inhibit those activities), it's hard to tell which of their activities are a net benefit to our country. My guess is that most Americans would expect that they sometimes do things that aren't legal, but that generally they are at least intending to do it with the best interest of our country in mind. That second part is the primary reason why they aren't being wholesale shut down, and why they're able to get away with things like lying to congress.
- FerretFred 6y ago> ..arrange for some kind of warning if the back door gets discovered and manipulated by adversaries "Hello Support? My computer just popped up a message to say that a bad actor has taken over my computer; should I reboot it?"
- duxup 6y agoI would expect they do, and I'm not entirely against it depending on the circumstances around it and so forth. To me a 'back door' could range from 'don't fix that bug for a week' to 'push this update to this user' to some absurd 'hey can you add this remote desktop client to your code, the password has to be 1234'. By no means is it a light thing to do but I do believe there is a range of actions that would constitute a 'back door' to me. Granted I'm all for more congressional oversight and I'd like to see MUCH more aggressive congressional action.
- programbreeding 6y agoThe problem with your first and third examples is that it leaves it open and vulnerable to anyone other than the NSA. Like if a "backdoor" is left open for encryption, as soon as it's discovered then that door is open to anyone. The problem with your second example, targeting a specific user, is that they're doing this without any kind of warrant.
- duxup 6y agoI completely agree on all points.
- stonepresto 6y agoRoot everything. FOSS all the things. Tear everything apart. There will always be a BBEG, no matter what part of the world you are in or what sort of government you live under. You are the only one who acts in your best interest.
- deleted 6y ago[deleted]
- fsflover 6y ago> You are the only one who acts in your best interest. No, you aren't. And it's impossible to do everything alone. https://news.ycombinator.com/item?id=24881988 https://news.ycombinator.com/item?id=24881988
- stonepresto 6y agoI agree with the second part of your statement, but I think being alone in acting in your own best interest still holds. Good projects such as those are a result of many similarly aligned self-interests. I'll admit I was being a bit dramatic, and as you have pointed out it's certainly more complex than a single sentence. I was trying to highlight that blindly trusting another human or organization can leave you vulnerable.
- jankiehodgpodge 6y agoFor most people, rooting makes them less secure not more. It all depends on who you're securing against.
- stonepresto 6y agoThat's certainly fair, especially if the password is then set to some variation of "password"... Although for some devices if you can root it, you probably also know methods of securing it.
- lucb1e 6y ago
- Gaelan 6y ago@dang Can we change the title to include "NSA"? It's silly that the headline doesn't say which spy agency.
- ChrisMarshallNY 6y agoWyden is great. The big issue with backdoors, is that it's only a matter of time, before they become "front doors." Presented for your approval. Imagine, if you will, a software engineer; probably based in the US, that writes a backdoor into equipment used to manage a banking transaction network. This is a fairly natural place to have it, as "follow the money" is a classic forensic technique. Of course, access to this network could net nefarious (probably non-state) actors a lot of money. Said software engineer suddenly quits and buys a Bugatti. The back door is now a front door, and it's baked into some hardware that can't easily be changed, as no one trusts the patches, now.
- staplers 6y agois that it's only a matter of time, before they become "front doors." Look no further than Plaid banking service. They collect your banking login information. I guarantee there are blanket warrants to monitor accounts from multiple agencies.
- xxpor 6y agoYou don't even need a warrant for that. SARs are a thing. It could potentially even be considered business records, which are just subject to a subpoena, not a warrant. The police have been able to request phone records since forever. https://en.wikipedia.org/wiki/Third-party_doctrine https://en.wikipedia.org/wiki/Third-party_doctrine
- Tistel 6y agoThey say it’s for large scale cloud management, but, think of worst case scenario: https://www.zdnet.com/article/minix-intels-hidden-in-chip-operating-system/ https://www.zdnet.com/article/minix-intels-hidden-in-chip-op... It seems like a massive waste of chip transistors and R&D with limited gain. The hidden minix OS runs at a higher privilege than your host OS. Even if your data is encrypted, any time you decrypt locally, they can see it. I get it, they are looking for bad guys, what if the bad guys take over? There will be nowhere to hide. Yes, I am wearing a tinfoil hat.
- seibelj 6y agoOperate under the assumption that government is reading all of your text messages, internet history, payment history, and phone calls. Then when you need privacy, enhance as needed. Even if privacy technologies like VPN or Tor are compromised, the government is less likely to reveal in order to keep the fact they can do it secret. Good luck out there! It's an unfair and scary world, once you try to do anything non-conformist.
- fsflover 6y agoNo, you should try to have privacy at all times. Otherwise those who really need it will be in the minority and easily hacked.
- goatinaboat 6y agoEven if privacy technologies like VPN or Tor are compromised, the government is less likely to reveal in order to keep the fact they can do it secret That is what parallel construction exists for. Also known as fruit of the poisoned tree.
- Threeve303 6y agoSpy agency denies performing main purpose for existing.
- netsec_burn 6y agoReminds me of one of my favorite comments on HN (when the NSA discouraged quickly adopting post-quantum cryptography): https://news.ycombinator.com/item?id=21587571 https://news.ycombinator.com/item?id=21587571
- crtasm 6y agoOff topic: anyone know why Reuters always 404s when I click on a link to it in Tor Browser? Desktop and Android.
- charliebrownau 6y agoGoverment + Central Banks + Corporations ARE THE PROBLEM, never the solution
- babesh 6y agoSo the US was exposed for doing what it accused China of doing.
- dariosalvi78 6y agoI thought the problem was Huawei...
- x87678r 6y agoI always assumed there would be insecurities in everything you buy and if there weren't backdoors it was normal for spooks in various nations to be able to crack it sooner or later. Using cloud services makes this even more likely. Does anyone really think they are 100% safe?
- haydonchurchill 6y agoDoes anyone really believe that they don't add backdoors? If it's a major tech / internet business, they require access to a backdoor.
- aaron695 6y ago> The starkest example of the risks inherent in the NSA’s approach involved an encryption-system component known as Dual Elliptic Curve Only example perhaps. What other back doors have they done? Literal secret rooms where they tap data, these are not conventionally called backdoors. Nor are unpatched zero days the supplier originally didn't know about. I don't think any country can install literal backdoors on products without getting caught. Backdoors seem like a Hollywood thing straight out of WarGames. Why attack the Chinese or visa versa when you'd be basically working for them by damaging your own companies when you get caught.
- secfirstmd 6y agoCrypto AG and paying RSA come to mind.
- aaron695 6y agoI didn't know much about Crypto AG. Thanks, that's interesting. Also through encryption weaknesses. It's an interesting way to backdoor. https://en.wikipedia.org/wiki/Crypto_AG https://en.wikipedia.org/wiki/Crypto_AG
- inquirerofsorts 6y agoSome of the numerous Cisco vulnerabilities have all the hallmarks of government persuasion. Not to mention the wholesale hacking of their products bound for export: https://www.infoworld.com/article/2608141/snowden--the-nsa-planted-backdoors-in-cisco-products.html https://www.infoworld.com/article/2608141/snowden--the-nsa-p...
- aaron695 6y ago> Some of the numerous Cisco vulnerabilities have all the hallmarks of government persuasion. Is there a write up of the code analysis? It's interesting because I think it would be very hard to do without being caught retroactively. Easy to insert, but hard to cover up the fact it was inserted when specifically looked at. It would have to hide from fuzzers for instance. Easy to do, but hard to hide the fact your were hiding a bug.
- jchook 6y agoMaybe they reverse-engineered China's hardware backdoors and don't need additional backdoors now.
- c54 6y agoThought this was an article about ducks who are spies[0]... too bad. [0] eg http://agentyduck.blogspot.com/ http://agentyduck.blogspot.com/
- peterwwillis 6y agoIf, hypothetically, you worked for one of these vendors, then, hypothetically, you might find that while waiting for a shipment of new product test gear to your lab, a shipment from California to Maryland may get waylayed - by U.S. Customs, in Texas. Two weeks later you finally get your gear. And you don't talk about it outside your immediate team. Such is life in a big company. Hypothetically.
- ck2 6y agoMeanwhile government can read any email without a warrant that is six months old for the past THREE DECADES Why does the press never mention this? It's in part why there was an email server in the basement, most people should have theirs there but gmail mostly won that battle due to spam management.
- known 6y agoAn excellent movie on how Israel/US/EU used a Computer virus to destroy Centrifuges in Iran Nuclear Plants https://yts.mx/movies/zero-days-2016 https://yts.mx/movies/zero-days-2016
- mechnesium 6y agoI believe the US government is actively undermining products that don't have such backdoors. For example, the US DoD now classifies JetBrains products as prohibited, which trickles down from the 2020 National Defense Authorization Act. I'm guessing this is because they are foreign-controlled, and refuse to comply with National Security Letters requesting backdoor insertions.
- NewOrderNow 6y agoYou are a cunt
- dang 6y agoIt looks like we have to ban you again. It's too bad, and nothing personal, but you just can't break the site rules like this. https://news.ycombinator.com/newsguidelines.html https://news.ycombinator.com/newsguidelines.html
- NewOrderNow 6y agoI hope you get raped