35 ms·
Snowden leak: Cavium networking hardware may contain NSA backdoor
- perihelions 3y agoHow the NSA successfully manage to prevent the Washington Post and friends from discovering and reporting on this malicious backdoor? They've been sitting on these documents for a decade. Are the journalists just that *uncurious* about the deep contents of the documents they hold exclusive access to? Was this some kind of organizational failing?
- erdos4d 3y agoWaPo, NYT, et. al. are tied to DOD and the intel community. They are the anonymous sources that provide many of their story ideas as well as quotes and sourcing. That doesn't come for free.
- syndicatedjelly 3y agoDo you think there was a list in the document neatly titled “NSA_BACKDOORS_DONT_SHARE” or something?
- hammock 3y agoMore likely an IC plant in the editorial office that said "NSA Backdoors Don't Share." NSA also pays the owner of the Washington Post upwards of $10 billion for cloud services
- gruez 3y ago>NSA also pays the owner of the Washington Post upwards of $10 billion for cloud services That's not the only publication that had access to the documents. From wikipedia >the first of Snowden's documents were published simultaneously by The Washington Post and The Guardian. [...] The disclosure continued throughout 2013, and a small portion of the estimated full cache of documents was later published by other media outlets worldwide, most notably The New York Times (United States), the Canadian Broadcasting Corporation, the Australian Broadcasting Corporation, Der Spiegel (Germany), O Globo (Brazil), Le Monde (France), L'espresso (Italy), NRC Handelsblad (the Netherlands), Dagbladet (Norway), El País (Spain), and Sveriges Television (Sweden).
- dylan604 3y ago>More likely an IC plant in the editorial office that said "NSA Backdoors Don't Share." Wouldn't be more likely that a plant would actually not say that, but rather come up with something else? Seems much more likely that a plant would promote some other aspect of a leak that would be less damaging as the story. Or even possibly making part of the document dump disappear.
- deleted 3y ago[deleted]
- michaelt 3y agoI suspect when a trove of documents is big enough, newspaper readers lose interest before you run out of documents. I mean, even on this tech forum hardly anyone knows who Cavium are, let alone your average Washington Post reader.
- elif 3y agoMaybe the moral of the story is that future snowdens should leak to selected law firms instead of selected journalists? If there's one organization designed to comb through large documents for details and understand the impacts to potential parties, it is law organizations. Put 2-3 in time competition to make cases out of the documents and it will be a scramble race for justice.
- hcurtiss 3y agoLaw firms aren't terribly entrepreneurial. Absent somebody paying them their hourly rate, I suspect not a single document would be read. Newspapers regularly take risks deploying humans to investigate issues without any assurance there will be a story at the bottom, but even the newspaper business has less appetite for that these days (as an aside, I suspect it's that margin that the financial investors have exploited -- at the expense of high quality reporting).
- hammock 3y ago>Law firms aren't terribly entrepreneurial. Personal injury guys are the most entrepreneurial people I know...
- kube-system 3y agoAnd they make money by going after low-hanging fruit. Ever wonder why they advertise 90%+ success rates and work on contingency? Because if your case isn't easy, you aren't their customer.
- 3y ago
- orangepurple 3y agoOperation Mockingbird never ended. Full stop. (2010) https://weirdshit.blog/2010/07/23/cointelpro-operation-mockingbird/ https://weirdshit.blog/2010/07/23/cointelpro-operation-mocki...
- BlueTemplar 3y agoWell, COINTELPRO certainly didn't : we've got recent examples about how the FBI monitored the Parler group discussions that were planning the January 6 2021 United States Capitol rally - including convincing some of the most risky elements to not participate, and (supposedly) warned Washington law enforcement about it well in advance. Which is fine I guess, as long as it doesn't go into the more abusive examples listed. One thing that jumped at me when (re-?)reading the letter to MLK from the FBI : first you have some very informal speech : "look into your heart", "you are done", "you are [] an evil, abnormal beast", "there is only one thing for you left to do" Then SUDDENLY : "You have just 34 days in which to do it (this exact number has been selected for a specific reason, it has definite practical significance)." Lol, talk about a change in tone, I wonder if MLK noticed it ? (The specific reason being Christmas, but still...)
- throwawayq3423 3y agoCold war history really broke people's brains. Yes this took place in the 1970s, no such thing happens today.
- garba_dlm 3y ago> Was this some kind of organizational failing? sure, why not. and while we're on this deluded train: Julian Assange's legal problems are not political persecution
- kome 3y agomainstream journalists are incredibly unreliable. it's absolutely clear to everyone that you cannot trust nyt and similar publications. i never read them anyway, and when I do come across articles on topics I'm knowledgeable about, i'm appalled by how wrong they are.
- bigger_inside 3y agoexactly. When I read things I KNOW about, it's incredibly obvious that the news entertainment business (which WP and NYT and CNN and Fox all are) exist to serve the prejudices of their audience. A few times I made the mistake to let myself be interviewed by a newspaper who wanted an "expert" on something (flattering, but meh); something copletely benign and harmless, nothing political. They twisted my words to serve up stuff that fit what their "normal reader" already believed about the world.
- colordrops 3y agoIt's crazy to me that people pay for access to these outlets. I wouldn't pay for any content except from individual journalists and a few very small outlets, and even then, would immediately stop if things ever turn for the worse.
- dylan604 3y ago>i never read them anyway, and when I do come across articles on topics I'm knowledgeable about, i'm appalled by how wrong they are. I never do that, except when I do. What kind of soapbox are you trying to stand on. It looks more like a cardboard box collapsing under the weight of your own hubris. I get the suspicion of news outlets of any kind. It doesn't matter what stream the journalists are fished out of, but they cannot all be subject matter experts in all subjects. This is also an expectation full of hubris on your part.
- Workaccount2 3y agoModern journalists are just terminally online twitter heads. "Why go out or talk to anyone when I can just stay home and be on twitter all day!?!" It's the absolute worst outcome for journalism, and none of publications seem to care. If I had a publication the first thing I would do is ban twitter use (and probably go bankrupt because of it.)
- pangolinpouch 3y agoOur media companies are rife with intelligence agents. Corporate / State media has no incentive to make you the wiser.
- ekianjo 3y ago> Our media companies are run by intelligence agents Fixed that for you
- hangonhn 3y agoIt's quite a bit more subtle than that. News organization have their sources that are in the intelligence community. They use each other. Sometimes the journalist wants to use their sources for information. Other times their sources feed them disinformation disguised as information. Other times they want a back channel to leak some real information but can't be seem as coming from a government source. Being a good journalist is hard and often doesn't pay very well. I'm often remind of PG's essay on corporate PR and the media: http://www.paulgraham.com/submarine.html http://www.paulgraham.com/submarine.html
- the-dude 3y agoI have no sources at hand, but I understood the FBI/CIA is embedded within every major news org in the US.
- Clubber 3y agoThe twitter files showed government agencies were coercing Twitter into suppressing information. I would find it hard to believe they don't also coerce at newspapers, particularly with the cozy relationship they already have with "anonymous sources" from said agencies.
- throwawayq3423 3y ago> The twitter files showed government agencies were coercing Twitter into suppressing information. They very much did not. Twitter's own lawyers when pressed in court (the place where there are consequences for lying) admitted that nothing in the "Twitter Files" cited by Donald Trump actually show that the social media platform was a tool of government censorship. https://storage.courtlistener.com/recap/gov.uscourts.cand.387133/gov.uscourts.cand.387133.195.0.pdf https://storage.courtlistener.com/recap/gov.uscourts.cand.38...
- 45y54jh45 3y agoWell yes, why do you think the noise died after the initial hype of Snowden leaking the docs? Do you honestly believe the mechanisms of for-profit journalism lets journalists be journalists? They got to eat and in this world you don't eat by covering yesterdays news. NSA didn't have to lift a finger. Wait a few weeks and people move on to the next story, this should not be a shocking revelation to anyone.
- ben_w 3y agoThe British intelligence agencies forced the Guardian to literally shred the laptop with the contents while they were in the swing of running headlines about the things it was revealing. While the USA and the UK are different, I suspect there was a bit more difficult for the NSA than "didn't have to lift a finger".
- drak0n1c 3y agoClosed orgs can take years to find what takes an open source crowd mere days. Regardless of organizational competence.
- PKop 3y agoSome of them are deputies for the state. State-run-media, or Media-run-state, whichever you prefer. The FBI and CIA had agents inside Twitter and Facebook. Of course they have them inside news agencies as well. Part of it over time is access-media, the ones that play ball get the stories and info, the others get weeded out.
- throwawayq3423 3y agoThe casual nature of stating a completely impossible conspiracy theory has been common place online for years, HN news used to be immune. It's illegal for FBI or CIA to actively target a US company. Anyone doing so would be fired for cause.
- logicchains 3y agoIt's illegal to lie under oath to Congress, did James Clapper go to jail? It's illegal to sleep with underage girls, how many people on Epstein's client list went to jail?
- throwawayq3423 3y agoSo, rank and file gov employees will risk their jobs to break the law because powerful people away with it, why wouldn't they? Does that make sense to you? It doesn't to me.
- 0xDEF 3y agoWhy are you surprised that backdoors in "boring" non-consumer facing hardware didn't get much attention?
- some_random 3y agoSnowden leaked a shit ton of documents, the vast majority of which had absolutely nothing to do with any kind of NSA wrongdoing. Journalists then had to go through and try to figure out what these documents actually meant (which they frequently misunderstood). Obviously they're still doing it to today.
- mindslight 3y agoAs a general rule when criminal conspiracies are taken to task, they don't retain a right to privacy for their communications that aren't about the criminal conspiracy. Rather it all comes out in court. I understand why Snowden released the way he did, and given how it kept attention on the subject for longer than Binney/Klein it was probably the right call. But there should have also been an escrow/intent to dump the whole trove raw after some time period.
- some_random 3y agoDo you really think the entire American IC is a "criminal conspiracy", or are you just trying to justify the fact that Snowden is an angry and vindictive sharepoint admin who simply dumped everything he had access to without regard for what was actually in those documents?
- mindslight 3y agoYes. By the straightforward standards that non-governmental criminal conspiracies are prosecuted, a large chunk of the NSA is engaged in a criminal conspiracy. We don't hold back on prosecuting other criminal conspiracies just because their associations produce other results like financially supporting their communities and coaching their kids' soccer teams.
- wnoise 3y agoThe only way they're not is by the Nixonian "when the President does it, that means it's not illegal" standard.
- 0xDEF 3y ago
- what-no-tests 3y ago> Was this some kind of organizational failing? No...the organization is behaving exactly as intended.
- miguelazo 3y agoAre you kidding? WaPo serves the intelligence community. >After creation of the CIA in 1947, it enjoyed direct collaboration with many U.S. news organizations. But the agency faced a major challenge in October 1977, when—soon after leaving the Washington Post—famed Watergate reporter Carl Bernstein provided an extensive exposé in Rolling Stone. Citing CIA documents, Bernstein wrote that during the previous 25 years “more than 400 American journalists…have secretly carried out assignments for the Central Intelligence Agency.” He added: “The history of the CIA’s involvement with the American press continues to be shrouded by an official policy of obfuscation and deception.” Bernstein’s story tarnished the reputations of many journalists and media institutions, including the Washington Post and New York Times. While the CIA’s mission was widely assumed to involve “obfuscation and deception,” the mission of the nation’s finest newspapers was ostensibly the opposite. https://www.guernicamag.com/normon-solomon-why-the-washington-posts-new-ties-to-the-cia-are-so-ominous/ https://www.guernicamag.com/normon-solomon-why-the-washingto...
- pxc 3y agoThe WaPo is relentlessly pro-US and pro-'intelligence community' in its writings today, too. It's transparent. Idk how it could be missed, even without knowing the history. Just read a couple articles about contemporary whistleblowers or US involvement in the Syrian civil war or the war in Ukraine or whatever.
- mcpackieh 3y ago> It's transparent. Idk how it could be missed, Support or criticism for the intelligence community became very partisan during Trump's campaign and presidency. Once something like this becomes partisan, the average political creature loses some degree of rationality for it. The IC becomes patriotic good guys, stalwart defenders of American democracy standing up to fascism; their past and present malfeasance goes unnoticed, forgotten, or simply ignored. This is how the WaPo's relentless pro-IC stance could be missed; they've been telling a lot of people what they want to hear and all people are less critical and suspicious of things that support their biases and prejudices.
- wsc981 3y ago
- Consultant32452 3y agoSupposed news organizations openly employ spooks as commentators on things like foreign policy. Journalists knowingly report lies, acting as the mouthpiece of the government. We know at least one news organization had the whole Epstein story locked down and they buried it because they were afraid they’d lose access to the royal family for future news/puff pieces. You think you hate journalists enough, but you don’t.
- ramesh31 3y ago>How the NSA successfully manage to prevent the Washington Post and friends from discovering and reporting on this malicious backdoor? They've been sitting on these documents for a decade. Washington Post -> Bezos -> AWS -> Cavium Pretty simple to understand, really.
- luxuryballs 3y agothat moment you realize “democracy dies in darkness” is a mission statement
- KaiserPro 3y agoThe snowden leak was huge and reverberated for weeks. There were lots of followups. However at the time it was the more sexy things like tapping google's fibre and backdoors in cisco's kits that were more interesting. This is because the public could understand those things and therefore it sold papers. The difference between "cisco, dell and many other leading manufacturers shipped backdoors in their kit" and "cavium the small provider you've not really heard of" is large. Most people reading the snowden stuff will have assumed that the NSA had put in backdoors to most things.
- denton-scratch 3y agoI don't think the journos were lazy, and I don't think there was an organisational failing. The Guardian, in particular, evidently fell out with Snowden and his collaborators; they turned on him. I assume that was coordinated with Washpo and Spiegel. That is: I think there was a decision made, to stop publishing information from the Snowden trove. I don't know what the reason for the betrayal was. I'm pretty sure Alan Rusbridger knows though. He resigned as Editor-in-chief shortly after these events. I don't get why whistleblowers rely on newspaper publishers to unpack their leaks for the public; it's not as if the press are known for either their honesty or their scruples.
- jstarfish 3y ago> I don't get why whistleblowers rely on newspaper publishers to unpack their leaks for the public They have an interest in drama and a platform to publish on.
- chillbill 3y ago[dead]
- TheRealDunkirk 3y agoIn the US, we have this passionate fantasy about Woodward and Bernstein and the Post and the Pulitzer and the movie and Redford and Hoffman and the Academy Award, about how the Press played the part of the "fourth estate" as the Founders intended, and rooted out a corrupt politician, and forced him to resign. It's all bullshit. The people who broke into the Watergate Hotel were CIA, Woodward was formerly CIA, and "Deepthroat" was a Deputy Director of the FBI. It was all a deep state plot to get rid of Nixon. Any time the deep state wants to get rid of a politician, the "press" does its "job" by exposing things. When the deep state likes a politician, the "press" ALSO does its "job" by covering things up. Look absolutely no further than Hunter Biden. The hypocrisy is utterly astounding, even to someone who is deeply cynical at this point. The rest of the US needs to wake up to the fact that the press is just another branch of the deep state, and stop pretending that there's ANYTHING useful being fed to us through ANY of the large media corporations.
- calgarymicro 3y agoWow, the deep state is so powerful that they got Nixon to say on tape that he was going to try to get the CIA to falsely use national security as an excuse to stonewall an FBI investigation. Poor innocent Nixon was no match for their telepathic powers.
- TheRealDunkirk 3y agoWhoosh. You went clean over my head, anyway.
- calgarymicro 3y agoWhat's so hard to understand? Nixon was literally caught on tape[0] conspiring to cover up CREEP payments; it's a bit funny to claim Watergate was all a deep stage conspiracy to screw Nixon when he was recorded committing crimes. [0]https://watergate.info/1972/06/23/the-smoking-gun-tape.html https://watergate.info/1972/06/23/the-smoking-gun-tape.html
- 3y ago
- rdtsc 3y agoWP is a very close ally to the government agencies in general. That's where it gets those juicy "anonymous government sources claim ..." news. If WP all of sudden wanted to prevent democracy from dying "in darkness" as their motto says, it would mean to start digging a lot harder going against the government as a whole. Don't think they are prepared for it.
- theropost 3y agoLack of real journalistic resources - Meta has more "journalists" then the Washington Post.
- londons_explore 3y agoI personally suspect that security services visited the newspapers a few days after the leak [1], and ever since then, every article has been about stuff that wouldn't be a surprise to rival security services. Sure - it was a surprise to the public. But rival security services I'm sure would expect US controlled backdoors in US made technology. [1]: https://www.theguardian.com/uk-news/2014/jan/31/footage-released-guardian-editors-snowden-hard-drives-gchq https://www.theguardian.com/uk-news/2014/jan/31/footage-rele...
- boomboomsubban 3y agoAccording to Appelbaum, the person publishing these new leaks, >Primarily these documents remain unpublished because the journalists who hold them fear they will be considered disloyal or even that they will be legally punished Whether that's true I can't say. But as a reminder, despite constant claims that Assange is being extradited over hacking charges, something like 17 of his 18 charges are over publishing documents.
- rdtsc 3y agoThey are now part of Marvell Technology https://en.wikipedia.org/wiki/Cavium https://en.wikipedia.org/wiki/Cavium Wonder if agreeing to enable NSA backdoors they agreed to be compensated when eventually that fact is leaked. "If nobody starts buying your chips, don't worry, we will! ... and then promptly throw them into the recycling bin" Also interesting is if Marvell knew their acquired tech had this "cool feature".
- deleted 3y ago[deleted]
- KingLancelot 3y ago[dead]
- rvnx 3y agoThe agreement with the NSA is more likely like this: "if you don't comply, you will get arrested / fined for whatever reason (crypto exports issues or failure to comply with the law), maybe even by another authority, or journalists may discover your little things about X. If you comply we may help you with some tips occasionally to make sure our partnership is working well, or just not reveal your trade secrets to your competitors"
- delfinom 3y agoYea, people forget we literally have a secret kangaroo FISA court being abused to issue "national security letters" with rubber stamp that demanded compliance and threatened to throw you in jail for resisting and/or talking about it. The Patriot Act largely was responsible for it, but even now they've wiggled to other avenues since the Patriot Act expired.
- bananapub 3y agoer...what? why do you think any of that has happened? we already saw this happen in public once with Qwest: https://www.eff.org/deeplinks/2007/10/qwest-ceo-nsa-punished-qwest-refusing-participate-illegal-surveillance-pre-9-11 https://www.eff.org/deeplinks/2007/10/qwest-ceo-nsa-punished...
- colatkinson 3y agoMastodon link for those so inclined: https://ioc.exchange/@matthew_d_green/111091979256440306 https://ioc.exchange/@matthew_d_green/111091979256440306
- JanSolo 3y agoThe tweet seems to imply that the entire Ubiquiti Networks line of network hardware could be compromised. That's a shame; I was thinking of installing some in my house. I'm sure that Ubiquiti's customers will not be happy if they find out that the US Govt can access their private data.
- sneak 3y agoUbiquiti is all cloud based. If the government wants in to your auto-updating ubnt hardware, it's just a simple court order away. They don't need a backdoor.
- anderiv 3y agoIt may be auto-updating by default, but that can be trivially disabled. Likewise, their cloud connectivity/management is optional. I'm running without issue multiple air-gapped Ubnt networks using their self-hosted controller software.
- fyloraspit 3y agoYeh but it is still closed source, no? I guess if it is air gapped that could be fine, but we are talking mid level network gear here, so for 99% of its use, it isn't air gapped. It is enabling broader connectivity. So you would have to trust the closed source software at some point.
- sneak 3y agoIf it's airgapped, what do you care about it being backdoored?
- lofaszvanitt 3y agoAirgapped doesn't necessarily mean it can't be accessed remotely...
- sneak 3y ago
- fidotron 3y agoOn a technical level this wouldn't be too surprising. Cavium hardware has things like configurable/programmable in hardware hashing of packets which can then be used by the (much slower, but in the Cavium case numerous) CPUs to decide how to handle it. Their SoCs contain enough that hiding something on there would not be impossible, and using the hashing/routing etc. that enabled performance requires trusting blobs from Cavium.
- ChrisArchitect 3y ago[dupe]
- ChrisArchitect 3y agoMore discussion earlier over here: https://news.ycombinator.com/item?id=37562225 https://news.ycombinator.com/item?id=37562225
- moyix 3y agoThanks, I missed that! It looks like the previous discussion didn't touch on the Cavium news, though.
- deleted 3y ago[deleted]
- throwfaraway398 3y agoOriginal source from march 2022 : https://pure.tue.nl/ws/portalfiles/portal/197416841/20220325_Appelbaum_hf.pdf https://pure.tue.nl/ws/portalfiles/portal/197416841/20220325... page 71, thanks to wikipedia
- whalesalad 3y agomy edgerouter ER4 has a cavium processor =(
- obogobo 3y agoI'm so upset I loved this thing
- kome 3y ago[flagged]
- tristor 3y agoHuawei stuff is proven to be compromised, just not by NSA, instead by China.
- bigger_inside 3y agoa CIA claim isn't "proof". I've never seen anything to prove it, just imperialist hysterics
- bhouston 3y agoIt is fair to think that if the CIA is compromising US companies, then China is likely doing the same to Chinese companies. To assume otherwise is wishful thinking.
- MaKey 3y agoWhere is the proof?
- kube-system 3y agoChinese law requires Huawei to cooperate with their intelligence agencies.
- DiogenesKynikos 3y agoThat doesn't prove anything. You're just saying that Huawei could theoretically be compromised, but the above commenter asked for evidence.
- kube-system 3y agoThey are compromised in terms of governance, and their legal environment is the proof of this. Nobody has ever claimed that Huawei devices have backdoors. The issue is that the supply chain is compromised by legal means, not the hardware or software currently being shipped has technical vulnerabilities.
- hammock 3y agoEarlier this year, a man was sentenced to prison for six years for stealing Ubiquiti data that the NSA also apparently can steal. https://www.justice.gov/usao-sdny/pr/former-employee-technology-company-sentenced-six-years-prison-stealing-confidential https://www.justice.gov/usao-sdny/pr/former-employee-technol...
- acdha 3y agoLeaving out the extortion part makes it very hard to read your comment as being made in good faith.
- hammock 3y agoLearn about Qwest if you think NSA doesn't also extort to get what they want: https://www.eff.org/deeplinks/2007/10/qwest-ceo-nsa-punished-qwest-refusing-participate-illegal-surveillance-pre-9-11 https://www.eff.org/deeplinks/2007/10/qwest-ceo-nsa-punished...
- acdha 3y agoOh, I remember when that first came out. I’m not defending the NSA but criticizing the idea that it’s somehow unfair for some dude to go to jail for trying to extort his former employer. The NSA misconduct is a much less clear-cut question of Congressional approval and oversight - similar to how it’s not as simple as a murder charge when a soldier is accused of a war crime.
- 2OEH8eoCRo0 3y agoDo we need to do this every day?
- ReactiveJelly 3y agoEvery fucking day until democracy kicks in.
- zimmerfrei 3y agoMore interestingly, Cavium (now Marvell) also designed and manufactured the HSMs which are used by the top cloud providers (such as AWS, GCP, possibly Azure too), to hold the most critical private keys: https://www.prnewswire.com/news-releases/caviums-liquidsecurity-hsm-enables-hybrid-cloud-users-to-synchronize-keys-between-aws-cloudhsm-and-private-clouds-300631079.html https://www.prnewswire.com/news-releases/caviums-liquidsecur...
- api 3y agoIs there anyone here who actually thought cloud provider HSMs were secure against the provider itself or whatever nation state(s) have jurisdiction over it? It would never occur to me to even suspect that. I assume that anything I do in the cloud is absolutely transparent to the cloud provider unless it's running homomorphic encryption, which is still too slow and limited to do much that is useful. I would trust them to be secure against the average "hacker" though, so they do serve some purpose. If your threat model includes nation states then you should not be trusting cloud providers at all.
- enkid 3y agoIf your threat model includes the nation state where you physical infrastructure is, you're hosed.
- api 3y agoLiterally hosed. There's a funny jargon term "rubber hose cryptography" that's used to refer to the cryptanalysis method where you beat someone with a rubber hose until they give you the key. It's 100% effective against all forms of cryptography including even post-quantum algorithms.
- dmayle 3y agoThat's actually not true. It can do nothing about M of N cryptography. (That's when a key is broken up such that there are N parts, and at least M (less than N) are required to decrypt. It doesn't matter how many rubber hoses you have, one person can fully divulge or give access to their key and it's still safe.
- belter 3y agoOk the claim is the CPU was compromised and they were using ARM based tech. Is then ARM compromised? Cavium is now Marvell Technology.
- moyix 3y agoARM just licenses the ISA and provides some reference designs. Individual manufacturers can (and often do) add their own extensions and design the actual chips.
- SV_BubbleTime 3y agoAnd peripherals that have direct CPU and memory access. You could easily design a “backdoor peripheral” to a completely bulletproof CPU.
- Fnoord 3y ago> Ok the claim is the CPU was compromised and they using ARM based tech. MIPS and ARM. And Linux MIPS doesn't even have DEP and ASLR.
- monocasa 3y agoOr other elements of an SoC. Biased RNG would be a good bet.
- squarefoot 3y agoWhen I buy something electronic, my approach is "everything that is closed and goes online will be used to spy on people". It may seem a stretch, but governments can't exercise power over something they cannot control, and truly private communications would take away some of that control. To me there are no conspiracy theories or other strange reasons for being able to decrypt any seemingly private information except the will to preserve the status quo at any cost, which implies knowing in advance what a potential adversary may think or do. I would expect every device to be bugged for that reason, including all cellphones and computers and associated hardware, from CPUs with closed subsystems down to network chipsets with closed firmware. There will be no way to ensure private communications until someone will find a way to make a device which is 100% open and auditable from the operating system to the CPU, from all chipsets down to the last screw.
- iballing 3y ago“100% open and auditable from the operating system to the cpu” is the main goal of the Betrusted project: https://betrusted.io/ https://betrusted.io/
- ramesh31 3y ago>“100% open and auditable from the operating system to the cpu” is the main goal of the Betrusted project: https://betrusted.io/ https://betrusted.io/ Hopefully there's a 4G version coming. This seems too good to be true.
- RF_Savage 3y agoThe 4G modem is exceedingly unlikely to be audittable. Something like srsUE is not welcome on many telcos networks and requires some decently beefy hardware to run.
- 0xCMP 3y agoIt's possible to modify it and add a 4G modem, but that would probably be third-party. The creators of the project suggest using your phone's hotspot if you need connectivity when not connected to Wi-fi (something I heard in interviews they gave).
- convivialdingo 3y agoLooking more closely at this, the backdoor is almost certainly based on the back-doored random number generator, Dual_EC_DRBG, which is implemented as NIST SP 800-90A. From Wiki: >>> NIST SP 800-90A ("SP" stands for "special publication") is a publication by the National Institute of Standards and Technology with the title Recommendation for Random Number Generation Using Deterministic Random Bit Generators. The publication contains the specification for three allegedly cryptographically secure pseudorandom number generators for use in cryptography: Hash DRBG (based on hash functions), HMAC DRBG (based on HMAC), and CTR DRBG (based on block ciphers in counter mode). Earlier versions included a fourth generator, Dual_EC_DRBG (based on elliptic curve cryptography). Dual_EC_DRBG was later reported to probably contain a kleptographic backdoor inserted by the United States National Security Agency (NSA). From Cavium's NIST FIPS-140-2, Section 3.3 [1] Approved and Allowed Algorithms: The cryptographic module supports the following FIPS Approved algorithms. *SP800-90 CTR DRBG Deterministic random number generation 32 1: https://csrc.nist.gov/csrc/media/projects/cryptographic-module-validation-program/documents/security-policies/140sp1369.pdf https://csrc.nist.gov/csrc/media/projects/cryptographic-modu...
- stephen_g 3y agoThat's a very specific module - one of Cavium's dozens and dozens of products. Hard to tell what it is, more information is needed.
- convivialdingo 3y agoWell, there's several Cavium devices that support the deprecated/back-doored Hash_DRBG. For example, these devices were validated for the completely appropriately named "SonicOS 6.2.5 for TZ, SM and NSA". Gotta appreciate the irony. Cavium CN7020 Hash DRBG Cavium CN7130 Hash DRBG Cavium Octeon Plus CN66XX Family Hash DRBG Cavium Octeon Plus CN68XX Family Hash DRBG I don't know if that's hardware support or just a software validation - but it's still interesting that they validated it. https://csrc.nist.gov/Projects/Cryptographic-Algorithm-Validation-Program/details?validation=3445 https://csrc.nist.gov/Projects/Cryptographic-Algorithm-Valid...
- one_shilling 3y agoVery impressive work by the NSA, if true. Both from a political and technical perspective. It's good to know that our intelligence services are doing what they're supposed to, and doing it well. However, as interesting as this revelation is, it's unfortunate that Snowden decided to defect to the Russians and share his stolen cache of top secret documents with them and China, using Western journalists as ideological cover. I look forward to the day when he is brought to justice for treason.
- oaththrowaway 3y ago[flagged]
- jklinger410 3y agoShilling indeed.
- Freestyler_3 3y agoYou can't hold it against someone that they don't want to be tortured/killed.
- empath-nirvana 3y agoNobody was going to torture or kill snowden. His risk was prison, no more.
- oaththrowaway 3y agoNobody gets tortured or killed in prison? Regardless of your thoughts on the guy, nobody deserves what Assange has gone through in custody. Same with Manning.
- wnoise 3y agoAfter Guantánamo, that's not a risk I'd like to take.
- miguelazo 3y agoBeing stranded in Moscow because the State Department cancels your passport while you're en route to Ecuador = "defection"? Cute.
- nonrandomstring 3y agoAnother tragic blow to the environment and economy. We treat these stories as if they were simple matters of politics and tech. But the blast radius is huge. When this happened to Cisco, and their value dropped to about 7% of the market they created, I passed massive dumpsters of Cisco gear in the car park, prematurely torn out of racks and consigned to crushing as e-waste. Has anyone done a serious cost analysis of just how hard this hits? If a foreign entity sabotaged our industry this way we'd take the battle right to them.
- chillbill 3y ago[dead]
- hnthrowaway0315 3y agoWhere can I find dumpsters of Cisco gears? I guess they are good targets to hack on.
- WhereIsTheTruth 3y agoWhy now? Looks like Snowden is being weaponized, wich might indicate that he is still part of the group he is denouncing, is he a psyop? What's the goal?
- r721 3y agoFrom one of Twitter replies: >... this is not new... It states in the article that this thesis from Jacob R. Appelbaum was released March 25, 2022. The only thing that makes these 'new' (?) is that electrospaces discussed September 14th https://twitter.com/vxunderground/status/1703995620250325405 https://twitter.com/vxunderground/status/1703995620250325405 Electrospaces article discussion: https://news.ycombinator.com/item?id=37562225 https://news.ycombinator.com/item?id=37562225
- WhereIsTheTruth 3y agoMy question was why is it relevant today, specially after Arm going public, is the Mi6 trying to cover himself by denouncing the NSA?
- r721 3y agoMatthew Green is a well-known cryptographer, apparently he read Electrospaces piece, and noticed a thing which is interesting from a cryptography angle. So he posted a thread on Twitter, moyix submitted it here and people upvoted it to #1. Where is the supposed conspiracy?
- jacknews 3y agoI'm extremely sure it's far from the only one, and the practice is not limited to the US govt.
- deleted 3y ago[deleted]
- rwmj 3y agoOn a technical level how would this work? Could it be observed by the router occasionally sending packets unsolicited to nsa.gov? [joke, obviously it wouldn't send them to a well-known address, but to some "unexpected" place] Or maybe when the router has to generate a private key [does it?] it would generate one with a flaw?
- shoe_meal 3y ago[flagged]
- ech0riginal 3y agoY’all really need to work on your finesse.
- dang 3y agoPlease don't troll.
- auntie_sam 3y ago[flagged]
- AndrewKemendo 3y agoGenuinely, at this point you should just assume 100% of your electronics are compromised by someone. If it’s not a government (yours or otherwise) then a corporation will fill the gaps (while in most cases also giving it to those governments) You should assume you have no privacy anywhere in your life.
- eimrine 3y agoI have a laptop with no communications functioning and I'm sure it is not compromised. The proof of it is openly stored the wallet.dat file with no any password.
- AndrewKemendo 3y agoIs the idea to challenge someone to prove you wrong? Or are you suggesting that there no way for one of the aforementioned groups to recover your data remotely should they have a focused desire to recover it?
- eimrine 3y agoIdea is to challenge someone to propose a hardware + OS which can be as secure being online. Probably it has to be OpenBSD and the latest architecture with open BIOS.
- 0xDEAFBEAD 3y agoIf the NSA had hardware backdoors everywhere, it seems to me there would be no need for TAO or hoards of 0-days. And yet we know from the Snowden leaks that the NSA invests a lot in that stuff, correct?
- samgranieri 3y agoSo in real life terms, what does this mean for people that own USG3s? If you're so inclined, replace it? Or not use the VPN feature in the Unifi admin console? Personally, I just forward all WireGuard traffic to another computer on my network and use https://github.com/burghardt/easy-wg-quick https://github.com/burghardt/easy-wg-quick to setup a simple VPN.
- stephen_g 3y agoWe don’t know which types of Cavium products may have vulnerabilities, which models or what the nature of it is (could be only applicable to certain features, sounds like possibly related to VPN acceleration). So absolutely no way to know whether anything needs to be done or not, unless you expect you’re at risk of a nation state actor having a reason to specifically target you, in which case it’d be wise to stop using it.
- BlueTemplar 3y agoWhat kind of people ? Your average person can't do squat if targeted by a state actor anyway (except complaining to their own state about it, and let them sort it out). It's another thing when it comes to resisting surveillance capitalism : https://web.archive.org/web/20180919021829/https://www.alexrad.me/discourse/why-rosyna-cant-take-a-movie-screenshot.html https://web.archive.org/web/20180919021829/https://www.alexr... It's completely disproportionate that Hollywood is making people lose control of their own computers because they are worried about copyright infringement !! That a boycott of Intel and Ryzen CPUs, "Trusted" Platform Modules, and Windows (8+) also probably makes the job of NSA/CIA/FBI harder (because they have likely backdoored them) is just a bonus. (Of course there's also a potential failure mode that some much more hostile actors might get their hands on some of these backdoors, but it doesn't seem worth worrying about it until we get a high profile example of that happening ?) Of course if you have the responsibility of, say, protecting your non-US company from industrial espionage, the situation is very different.
- einvolk 3y ago[flagged]
- 31337Logic 3y agoWow. This is massive!!
- declan_roberts 3y agoThe intelligence agency enjoyed a supremely underserved SURGE in popularity during the Trump era because they were seen as an enemy of Trump. Let's all get back to reality now. They LIE and influence US politics to preserve their operations (not political, it's self-preservation). If you see something like "100 former intelligence agents sign letter saying ..." then run, RUN!
- ZoomerCretin 3y agoI'm looking forward to someone explaining to me why Chinese telecom equipment should continue to be off limits. Is the problem that we are afraid of possible Chinese backdoors, or that Chinese telecom equipment isn't backdoored by the NSA? An interesting question I'd like answered: Are the TPM 2.0 modules that Microsoft is requiring for Windows 11 installs similarly backdoored? https://www.theverge.com/2013/6/6/4403868/nsa-fbi-mine-data-apple-google-facebook-microsoft-others-prism https://www.theverge.com/2013/6/6/4403868/nsa-fbi-mine-data-... I think it's a safe assumption that all American microprocessors have backdoors. What does this mean for OpSec? If I am a dissident (or garden-variety cyber criminal), how do I evade my online activities being tracked by a sufficiently determined team at the NSA? We've known (or have assumed to know) for years that CPUs produced by AMD, Intel, and Apple have backdoors. If my machine lacks any personally identifying information, only interacts through the internet through a network device that uses a VPN and encrypted tunneling, then I should be fine in spite of CPU/OS backdoors. However, using a VPN with encrypted tunneling doesn't seem to be enough if my router also has a backdoor, and the data or encryption keys can be intercepted and tied to the personal information I've given my ISP. Where do we go from here? Do I need a Loongson-based PC and a Chinese router on top of an encrypted VPN? Obviously we have to assume that these are all backdoored as well, but that shouldn't matter as my activities don't likely won't make me a target of the PRC.
- 0xDEAFBEAD 3y ago>We've known (or have assumed to know) for years that CPUs produced by AMD, Intel, and Apple have backdoors. What's the evidence for this? >Obviously we have to assume that these are all backdoored as well, but that shouldn't matter as my activities don't likely won't make me a target of the PRC. Elsewhere in this thread it was claimed that the NSA has hacked Huawei. The NSA could have stolen the backdoors then, or it could've analyzed e.g. Huawei's hardware independently.
- robbywashere_ 3y agocmd+F lawsuit 0 results?
- halyconWays 3y agoIf it's sold in a Western nation, the NSA has a backdoor in it, and probably everyone in the Five Eyes. If it's sold anywhere else, China has a backdoor in it.
- keyme 3y agoChina *also has a backdoor in to. FTFY
- xyst 3y agoIs this only limited to “USG” products? Or safe to assume UDM also impacted? edit: FUCK “ Quad-core ARM® Cortex®-A57 at 1.7 GHz” https://store.ui.com/us/en/pro/category/all-unifi-gateway-consoles/products/udm-pro https://store.ui.com/us/en/pro/category/all-unifi-gateway-co... People paying premium $$$ for this. UI better redesign and compensate users.
- dna_polymerase 3y agoCavium provides purpose-built chips used for the ER & USG products. The UDM line uses ARM chips, most likely built by Annapurna labs.
- Obscurity4340 3y agoJust want to point out that iMessage makes a lot more sense in this regard. iMessage is that skeleton key that was requested years ago in San Beradino
- SV_BubbleTime 3y agoThat was low stakes, they already had the shooters. What if that was theater?
- Obscurity4340 3y agoThat's the really annoying part and the massive cultural red herring: they already have such insane levels of access to the latest toys and technology or equipment plus institutional access to records and documents they can subpeona and warrant from a judgethat will basically yield everything after it is aquired, why the fuck do they need that remaining 0.00000001% of evidence that constitutes everybody's private data when they already have a slamdunk case because of said totalitarian access described above?
- Obscurity4340 3y ago+ the illegal but inscrutable parallel construction
- Obscurity4340 3y agoCan you elaborate on that? I thought everyone knew it was trying to set some bullshit precedent plainly?
- wnevets 3y agoSnowden also said Russia wasn't going to invade Ukraine in 2022.
- stephen_g 3y agoMost of the Ukrainian Government and military leaders were also pretty adamant Russia wouldn't invade either at that point.
- wnevets 3y agoIncorrect. Ukraine revamped their entire military and their relations with the West after Russia stole Crimea. Russian's 2 week war wouldn't be entering it's second year if Ukraine's government and military leadership were adamant they weren't going to be invaded.
- mardifoufs 3y agoThey still didn't think they would be invaded at that point in time.
- wnevets 3y agoRussia's buildup of equipment and personal began months if not over a year prior to the 2022 [1] invasion. The idea that Ukraine's military and the West didn't know this was happening is comical. If Ukraine didn't think there was going to be invasion we wouldn't be entering year two of what was supposed to be a two week special military operation. [1] https://en.wikipedia.org/wiki/Prelude_to_the_Russian_invasion_of_Ukraine https://en.wikipedia.org/wiki/Prelude_to_the_Russian_invasio...
- SV_BubbleTime 3y agoIs everyone living in Russia supposed to be a Russian military expert?
- wnevets 3y ago
- apienx 3y ago“You can't defend. You can't protect. The only thing you can do is detect and respond.” -- Bruce Schneier
- NelsonMinar 3y agoFor anyone wondering "what's the big deal" it's worth remembering the NSA has a bad track record of keeping their own hacking tools secure. https://en.wikipedia.org/wiki/The_Shadow_Brokers https://en.wikipedia.org/wiki/The_Shadow_Brokers It infuriates me the NSA actively works to undermine American security. Their brief is to protect us, not plant backdoors and then lose the keys.
- boffinAudio 3y ago>It infuriates me the NSA actively works to undermine American security. It infuriates me that the NSA actively works to undermine International security. Seriously.
- jokoon 3y agoI believe they do this because most critical softwares are American, and as long as the NSA has better offensive capabilities, it's better for the NSA if international defenses are low. I don't think china or Russia really have good offensive capabilities, so as long as it is the case, this helps the US maintain some form of cyberweapon supremacy. As long as china or small black hats don't do harm, they will not raise security standards.
- thewileyone 3y agoSo much projection when the US accuses China of backdoors ...
- Aerbil313 3y agoHahaha. That “concern” is only for you guys in the US. I live in a state which has conflicting interests with the US.
- unaindz 3y agoSo what if you are not in the US? If they manage to put a backdoor in any software or hardware you use you are affected. They could spy on you and trade that with your government or just lose the keys and now anyone can do it. PD:Also from outside US btw
- tamimio 3y agoNot even surprised, how would it be a surprise? Anyone in security field knows that hardware backdoors or even server OS memory injected backdoors are a thing and been for as long as electronics existed, but some neo-security folks get upset when you say most of the “secure” software they use isn’t really secure, chats like signal, emails like protonmail, or even VPNs, assume it’s compromised, but will it be worth it to expose that cover for what you did?
- RecycledEle 3y agoIt all contains back doors.
- dr-detroit 3y ago[dead]
- minzi 3y agoI don’t know much about security, especially at the hardware level. However, I have a question for those of you that do. Suppose you were given a healthy budget, a team, and a few years. Would you be able to build network hardware that did not contain back doors? How healthy would the budget need to be? How skilled would the team need to be? I assume you’d have to assume most external vendors are compromised and rebuild whatever you needed from them. What would that take?
- 6d6b73 3y agoImpossible. Sooner or later one of the 3 letter agencies would have somebody on your team and they would introduce multiple backdoors one way or another.
- c7DJTLrn 3y agoI don't think it would be that hard. There's RISC-V SBCs out there which the schematics are open for. I don't think it's correct to assume absolutely everything out there is backdoored/compromised. That would be an very difficult undertaking and word would get out. NSA target their attacks very finely.
- hedora 3y agoFirst, read “Reflections on trusting trust”. If you care about performance, then you need to start by building a fab. $100B+, and you’ll end up with government moles. So, I assume you don’t care about performance. If you keep stuff under 100MHz or so, then you can avoid complicated signal processing. Design for a old process, and tape out. Now, read up on decapping and reverse engineering old dies with garage-built microscopes. Make many copies of your chips, then decap a random sample and verify they are to spec by hand. Use the rest to build a computer that can verify the output of the microscope. You can print circuit boards using hobbyist kits on a laser printer. Since they are 1 or 2 sided, you can visually verify them. If you can find commercially available chips that are primitive enough for you to decap, scan, reverse engineer and verify, then use those instead (following the random destructive sampling procedure above). Good luck!
- I_am_tiberius 3y agoAnd people still believe Apple is secure because they say themselves. "Nobody" knows what their devices do in reality.
- AtNightWeCode 3y agoAt the end of the day. We need cryptography that is understandable. There is absolutely zero need for the complexity in this field that exists today. And we need something better than just private keys.
- andy_ppp 3y agoPresumably the NSA are in and out of everything in ways people haven’t even thought of yet. Back doors are great but I’m not convinced they need them!
- w7 3y agoIs this not just related to the Dual_EC_DRBG and other tainted RNG issues we've known about, and mitigated, for years? You can see discussion on this going on as far back as 2015, explicitly in regards to what "SIGINT enabled" means and Cavium: https://www.metzdowd.com/pipermail/cryptography/2015-December/027657.html https://www.metzdowd.com/pipermail/cryptography/2015-Decembe... Am I missing something here? People are talking as if there is some new backdoor that's somehow avoided detection. Did everyone just miss this discussion in 2015? Discussion of the "Sigint Enabling Project" goes as far back as 2013 on HN itself.
- jdblair 3y agoHelp me out here: if my network hardware is compromised, but all of my communication is encrypted, that leaves… traffic analysis? hoovering up the data and storing it to decrypt in the future when it becomes feasible? using the router as a foothold to attack the rest of my network? The first two are already happening for data that leaves my LAN. Unencrypted data on my LAN is vulnerable, and there is plenty of unencrypted traffic on my LAN in practice. Is that the risk?
- jdblair 3y agostill thinking… if the three-letter-agency has compromised the random number generator, then that means all traffic encrypted by the router may be easier to crack. What data is encrypted on the router? VPNs, for one. So a VPN, and all the plaintext traffic sent over it, could be made vulnerable.
- 0xDEAFBEAD 3y ago>What data is encrypted on the router? VPNs, for one. What sort of VPN are we talking about?
- thenickdude 3y agoYou can run OpenVPN or Wireguard directly on Ubiquiti network equipment for example, and some Ubiquiti EdgeRouter equipment has Cavium CPUs
- someonehere 3y agoI think I had read the three letter agency is storing this kind of data somewhere in a database for later technologies to decipher. So I’d assume they could snoop packets and store that data elsewhere. Whenever they harness quantum computing I could assume they put that stored data of yours through it and decrypt it all.
- jdblair 3y agobut they’re already storing data off the IXs, why do they need to target my router?
- azinman2 3y agoIf your threat model is Nation states, then you probably have a lot more to worry about than this chip, including compromising employees which is way easier, cheaper, and more effective.
- Havoc 3y agoThe risk impact isn’t just nation states though. Intentionally weakened hardware makes you more vulnerable across the entire threat actor spectrum. Any of them could stumble across it whether through skill or luck.
- pwarner 3y agoMaybe there's something sinister here, or maybe Cavium and other similar network chips can be used for sigint, as well as many other things. Basically these are chips designed to look at every packet and can be programmed to take action on them. One could program a chip like this to find all the packages from user X and send an extra copy over to user Y (NSA). It's possible all this tweet means is that these NP chips are powerful and flexible enough to perform sigint. I wonder if this is like saying Intel CPUs can be used to evil things. Or C. Of course it's possible there is a back door, but that seems like the less likely scenario.
- greatNespresso 3y agoI wonder, how would one find out such backdoors at the CPU level? And also, are Snowden's leaked documents archived somewhere?
- deleted 3y ago[deleted]
- deleted 3y ago[deleted]
- purplecabbage77 3y agoThe linked tweet screenshots a blog post[1] that is an analysis of a pHd thesis[2] [1] - https://www.electrospaces.net/2023/09/some-new-snippets-from-snowden-documents.html https://www.electrospaces.net/2023/09/some-new-snippets-from... [2] - https://pure.tue.nl/ws/portalfiles/portal/197416841/20220325_Appelbaum_hf.pdf https://pure.tue.nl/ws/portalfiles/portal/197416841/20220325...
- Condition1952 3y agoI was looking forward to using a NETGATE 1100 PFSENSE+ SECURITY GATEWAY. It’s full of Marvell SoC. I guess I can spare myself the money
- sim7c00 3y agoDidn't read all the leaks but it seems a bit wild to conclude a vendor implemented a backdoor purposefully. There's some been found ofcourse, but simply being SIGINT capable, why does that imply 'backdoor'.? If they have a nice exploit for the device it would also make it SIGINT capable no? without the vendor's cooperation (apart perhaps from a buggy implementation.) If you have the chip, you can find the backdoor... if you cannot find it, you can't conclude its actually there. There's ways to analyse chips to see if they are backdoored. Decapping, fuzzing and whatnot. Simply basing such of a conclusion from a few lines in a document seems a bit off to me... Did anyone actually find the thing??
- Proziam 3y ago[1] Everyone gets asked to implement backdoors in this game. This includes games companies like [2] Riot Games and the popularly recognized cases of apps like [3] TikTok and [4] Snapchat. It's also worth noting, people assume (wrongly) that only China wants access to this data, the Feds are more than happy to strong arm people via [5] NSA letters (or other means as in [3]). [1] https://www.youtube.com/watch?v=wwRYyWn7BEo https://www.youtube.com/watch?v=wwRYyWn7BEo [2] https://www.wsj.com/articles/if-you-play-videogames-china-may-be-spying-on-you-11603926979 https://www.wsj.com/articles/if-you-play-videogames-china-ma... [3] https://gizmodo.com/tiktok-cfius-draft-agreement-shows-spying-requests-1850759715 https://gizmodo.com/tiktok-cfius-draft-agreement-shows-spyin... [4] https://www.cnn.com/2019/12/30/politics/army-tiktok-banned/index.html https://www.cnn.com/2019/12/30/politics/army-tiktok-banned/i... [5] https://www.theguardian.com/world/2014/mar/19/us-tech-giants-knew-nsa-data-collection-rajesh-de https://www.theguardian.com/world/2014/mar/19/us-tech-giants...
- sim7c00 3y agothanks for the background info thats some insightful reads. theres a defcon talk about chip decapping which us alsl very telling on this matter. even if they dont get asked companies also get infiltrated actively and are victimised. the difference is sometimes really hard to tell with the lacking inside info. its a weird game going on for sure. thanks
- deleted 3y ago[deleted]
- scrumlord 3y ago[dead]