Fixing NIC is not as easy as fixing software.
Fixing NIC is not as easy as fixing software.
And finally, why do any of this when you can almost definitely just issue a gag order to a legal council, or behind-the-door threats to a foreign government agency to tow the line, or any number of things? You're dealing with governments who have immense global influence, not scrappy hackers who only have their wits and old laptops about them.
I'm not saying agencies don't have exploits, or they don't use them, or they don't spy on a lot of data, or that even some backdoors aren't real. But if you're looking a NIC offload device, immediately claim "Wiretapping", and can't actually explain how it wiretaps anything or what the attack model is, it's really just random speculation and fear mongering.
Purely theoretical (and I'm not a crypto guy, so please do correct me if this is nonsense), but imagine a scheme whereby the IV is chosen to be the first few bytes of the private key xor the port tuple.
This could reduce the difficulty of brute forcing the key, and no extra traffic need be generated - we already know that the NSA operates passive observers, and has even placed such systems inside corporate networks in the past.
EDIT: As to why they'd do this instead of getting a gag order - because they can? Because there's less oversight? Safest to assume that any technical capability will be abused sooner or later.
Again, the NIC doesn't choose the IV. It is given an IV by the host system, which is derived from key exchange in software, and that IV must match what the other side of the link derives from its own key exchange operation. It has no choice but to use the IV given. Otherwise, the two parties can't communicate. So the NIC would have to attack the host system somehow to engage in this attack, but then it could just steal a private key anyway and get all communications forever. This is basic Diffie-Hellman/TLS 101.
This kind of "I'm not an expert, but let me make up a scenario completely divorced from reality..." thing is what I'm talking about when I say speculation/FUD. It sounds sufficiently "techie smart" to pass a trivial smell test but otherwise instantly falls apart.
> As to why they'd do this instead of getting a gag order - because they can? Because there's less oversight? Safest to assume that any technical capability will be abused sooner or later.
Any person in your life that you know could suddenly commit a horrible crime, just "because they can." Do you think they will? Is that reason to assume they will? "Because they can" ignores a basic aspect of how decisions are made, which is understanding their motivations and reasoning.
And less oversight from what? These gag orders are already enforced in secret courts. Governments exert pressure on each other, behind closed doors and through agreements like trade sanctions, to force other governments to comply. Theres's already "no oversight" in the process, by design it avoids oversight. Spooks can literally walk into your datacenter and pull a rack out of the cage and there's nothing you can do about it unless you want to get thrown in a dark hole for 500 years. Even if they had to resort to techie tricks, why is the scenario you imagine any more plausible than a thousand simpler, alternative options? Multi-million dollar corporations get ransomware'd all the time, and it's not like the culprits need hardware backdoors to do it.
Again: these agencies have exploits, and for a reason. They certainly use them. They have backdoors. That doesn't mean we just get to turn our brains off the instant something we don't understand mildly spooks us and assign complete impossibilities as the culprit. You're not far from just doing high-brow "lizard people control society" stuff at that point.
They can't change the algorithm or other NICs that don't offload the encryption/decryption wouldn't be able to successfully decrypt it. They couldn't send "extra" packets with the key somewhere else without someone very easily detecting that anomalous traffic not being generated by the system itself.
With QUIC there are almost no-unencrypted fields by design, and those have very firm well defined meanings, so to inject steganographic hidden copies of the key in the packets themselves is infeasible. Maybe you could sneak something out by changing source ports but that's risky, and liable to be detected as well.
So that leaves side channels, which is basically only a timing channel for remote attackers in this case. At the speeds and packet throughput where hardware acceleration of the crypto matters, any buffers in the first switch and/or router that packet hits will remove the precision required for any level of intentional timing attack that could be introduced without detection.
So no it almost certainly couldn't have a vulnerability like that unless the crypto algorithms themselves are broken, in that case this whole discussion is moot as it doesn't matter if its accelerated or not.
> Fixing NIC is not as easy as fixing software
This kind of thing is frequently implemented in FPGAs which can be updated with firmware. The firmware will likely be closed source, but that hasn't stopped people before from fixing firmwares without the original manufacturers knowledge or consent.
It's a lot more work but turns out the people that would be targeted by an attack fall into two categories, those who have the financial ability to pay for a security team to handle these kinds of vulnerabilities in house (or at least mitigate them) and normal people who couldn't bear the brunt of a nation state targeting them even if this one vulnerability didn't exist.
The NSA has been caught doing some seriously shady things we all know that, and no one is going to seriously argue they've stopped trying and developing new things, but it's not even close to reasonable to assume that any paper that has "crypto" present in it is a conspiracy from the NSA or any other intelligence agency.
Why would it matter if the traffic is detected? The companies owning the hardware are usually working with the NSA or compelled to do so, so the extra traffic is expected: https://archive.nytimes.com/www.nytimes.com/interactive/2013...
You can see part of the budget is straight out putting the backdoors in the VPN/web encryption chips design.
What's the point of those down voting comments when there is clearly an evidence that those things happened in the past.
In any case, security track record of crypto offload NICs is pretty good.
But when it is found, it can be easily fixed
> In any case, security track record of crypto offload NICs is pretty good.
Maybe because the only way to see what it does is to use an electron microscope?