Now if only they'd turn this lens on American-made devices which are likewise opaque, insecure, and likely to be weaponized against us as soon as security updates stop....
Now if only they'd turn this lens on American-made devices which are likewise opaque, insecure, and likely to be weaponized against us as soon as security updates stop....
Fixed that for you. :/
https://www.wired.com/2016/01/new-discovery-around-juniper-b...
If my job were to ensure backdoor access to everything I could, at least to get started I'd sort a list of hardware vendors by marketshare.
At some point you have to think these are deliberate.
Network hardware is to operate in the adversarial landscape which is the open internet. It requires an extreme, exhaustive workflow to ensure bugs do not slip through. That we repeatedly see these failures does not raise confidence.
- 2016-01 https://tools.cisco.com/security/center/content/CiscoSecurit...
- 2018-03 https://www.cisco.com/c/en/us/support/docs/csa/cisco-sa-2018...
- 2018-10 https://www.cisco.com/c/en/us/support/docs/csa/cisco-sa-2018...
- 2019-07 https://tools.cisco.com/security/center/content/CiscoSecurit...
Edit: formatting
How? Even ignoring ASICs, I just don't see how it's possible. Even if you had no binary blobs anywhere (we are already in the wonderland), with process for turning source to binary, you need to trust compiler, cpu, flashing hardware and software and the whole lot of other things.
And that's all ignoring the fact that hiding bad stuff in open source is many orders of magnitude cheaper than finding it.
I don't think we have even a theoretical plan for fixing computer security, it just becomes ML bots arena.
I think we do, but the implications of it are terrifying, overwhelming and just make people shrug and say "That'll never happen".
How I see it there are two sides.
Those who want a functioning technological society with all the benefits we believe in as hackers - transport, medicine, communications, planning... For that we'll have no choice but to make computers secure.
That side is "society".
In the other corner are those who do not want computers to be secure (despite what they say). They benefit from insecurity. These are;
- Criminals.
- Governments.
- Industry.
They are not aligned and fight amongst themselves. Only the criminals
are honest in that they don't pretend to want secure computing.
Governments and industry want secure computing for themselves, but not
for the others, or for society.For secure computing to ever happen three well organised, well funded and determined groups would have to lose against a disorganised, distributed, and poor remainder.
There are two things on our side to give us hope;
- That the enemy of my enemy is a temporary friend.
- Mathematics.
It’s the “distributed remainder” you are taking about, and what we are betting one is for the governments of the world to print so much money that everyone loses faith in them. That will act as a check on their power and they’ll need to start earning trust and support rather than taking it for granted.
"We should not solve this solvable problem because other problems exist" is false.
Meanwhile the other problems have solutions, like reproducible builds, so that the attacker not only has to compromise your compiler/CPU/hardware, they also have to compromise any others the output result gets compared by, or one of them will differ and the attack will be detected.
Without commenting on the truthiness of the comment you are replying to, you have constructed a strawman argument here. They weren't saying that the problem shouldn't be solved because other problems exist, rather that it might not be solvable b/c of so and so obstacles that don't seem to have a solution.
See: https://media.ccc.de/v/36c3-10690-open_source_is_insufficien...