NSA knew about Juniper backdoors and kept quiet about them
thenextweb.com
thenextweb.com
We've buried this submission because it is a dupe of https://news.ycombinator.com/item?id=10784595.
I often see submissions labeled as "[dupe]" and I've came across some of them myself. In these cases, what's the proper/best way of "marking" them as duplicates? Usually, I just hit "flag" but I feel that might not be the best way.
Thanks for all you do to keep HN awesome!
We're probably going to extend flagging to ask the user to pick from a list of reasons, one of which will be "duplicate", so this mechanism may change somewhat in the new year.
This is the first time I have seen any snowden document. I am stunned, they talk like black hat hackers, only caring about themselves and not the people using that tech.
1. https://www.documentcloud.org/documents/2653542-Juniper-Oppo...
Seriously? Then there's interesting[1] reading available[2].
[1] For various definitions of "interesting" ranging from "meh" to "OMGWTF" depending on your interpretation and politics.
[2] https://en.wikipedia.org/wiki/Global_surveillance_disclosure...
Finding/buying a zero day exploit is what most SIGINT intelligence organizations around the world could more or less easily achieve.
Penetrating an organization to the point of being able to introduce foreign code into their products which remained there for at least several years, as well as launch a fairly sophisticated crypto attack which would only benefit some one if they had the ability to tap into large scale internet traffic isn't something that many organizations if at all outside of the NSA-GCHQ coop should be able to achieve.
Russia and China are quite far behind, Germany and France don't have the budget (as far as appropriations goes, if they wanted too they could surely find the money), Israel could pull the exploit off both technically and operationally but it most likely lacks the ability to gather internet traffic on wide scale (it is probably one of the best out there as far as wireless sigint goes but it lacks the resources to be able to tap into world wide internet cable infrastructure) which makes it unlikely that they would introduce the VPN backdoor (unless it was for a very specific target, although Juniper together with ZTE pretty much rule the Iranian ISP market). This either means that either Russia and China are playing way beyond their presumed level of both capability and competency or there are other players most likely private hanging around the court which should is even more frightening.
Ofcourse there's still a chance that the NSA not only knew about those backdoors but actually introduce them but at the time being all the supportive documents just show that they discovered them rather than introduced them.
Israel is currently the 2nd largest exporter of cyber security solutions in the world it's mandatory military service means that virtually every employee of those companies served in their military intelligence or signal corps and since they are in the reserves until their mid 40's continues to do. Israel is in general is largely held as the strongest player at least as far as technical capabilities go after the US/UK coop. And they also have a very strong humint and general intelligence capabilities which would allow them to penetrate an organization like Juniper (Juniper having an R&D center in Israel also helps).
Is there another division in the government that reduces or allows the security of Americans to be so blatantly abused?
If the military had just given away the keys to our nukes, Someone's head would roll, but because this is tech, and congress only sees a black box, they can't see that the NSA is more often acting against Americans' best interests rather than for.
Why would the NSA infiltrate Juniper to change the Dual EC DBRG parameters, when the standard parameters are already exactly how they want them?
There is a good chance they noticed that their attacks against Dual_EC_DBRG weren't working - but to reveal that pre-Snowden would prove that they knew the private key and were exploiting it.
That said, I understand there was more than one back-door disclosed.
Chris Inglis, recently retired NSA Deputy Director, remarked that if we were
to score cyber the way we score soccer, the tally would be 462-456 twenty
minutes into the game, i.e., all offense. I will take his comment as confirming
at the highest level not only the dual use nature of cybersecurity but also
confirming that offense is where the innovations that only States can afford
is going on.
[1] http://geer.tinho.net/geer.blackhat.6viii14.txt[2] (among other credentials) CISO at In-Q-Tel