News: 1603928692

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

NSA: We've learned our lesson after foreign spies used one of our crypto backdoors – but we can't say how exactly

(2020/10/29)


It's said the NSA drew up a report on what it learned after a foreign government exploited a weak encryption scheme, championed by the US spying agency, in Juniper firewall software.

However, curiously enough, the NSA has been unable to find a copy of that report.

On Wednesday, Reuters reporter Joseph Menn published [1]an account of US Senator Ron Wyden's efforts to determine whether the NSA is still in the business of placing backdoors in US technology products.

Wyden (D-OR) opposes such efforts because, as the Juniper incident demonstrates, they can backfire, thereby harming national security, and because they diminish the appeal of American-made tech products.

But Wyden's inquiries, as a member of the Senate Intelligence Committee, have been stymied by lack of cooperation from the spy agency and the private sector. In June, Wyden and various colleagues [2]sent a letter to Juniper CEO Rami Rahim asking about "several likely backdoors in its NetScreen line of firewalls."

Juniper [3]acknowledged in 2015 that “unauthorized code” had been found in ScreenOS, which powers its NetScreen firewalls. It's been suggested that the code was in place since around 2008.

The Reuters report, citing a previously undisclosed statement to Congress from Juniper, claims that the networking biz acknowledged that "an unnamed national government had converted the mechanism first created by the NSA."

Wyden staffers in 2018 were told by the NSA that a "lessons learned" report about the incident had been written. But Wyden spokesperson Keith Chu told Reuters that the NSA now claims it can't find the file. Wyden's office did not immediately respond to a request for comment.

The reason this malicious code was able to decrypt ScreenOS VPN connections has been [4]attributed to Juniper's "decision to use the NSA-designed Dual EC Pseudorandom Number Generator."

Juniper's VPN security hole is proof that govt backdoors are bonkers [5]READ MORE

The company has yet to clarify exactly why it made that decision. Juniper did not respond to a request for comment.

When former NSA contractor Edward Snowden leaked agency secrets in 2013, Reuters [6]reported that years earlier security firm RSA, now part of storage biz EMC, had accepted a $10m contract with the NSA to use Dual Elliptic Curve, or Dual EC, encryption. RSA at the time [7]denied some of the claims without disputing the existence of the contract.

The NSA had been keen to see Dual EC adopted and worked with the US Commerce Department to promote it. But in 2007, two Microsoft researchers [8]reported there were serious flaws with the Dual Elliptic Curve Deterministic Random Bit Generator that led it to produce weak cryptography. By 2014, US standards agency NIST withdrew support for Dual EC.

Juniper at some point between 2008 and 2009 appears to have added Dual EC support to its products at the request of "a single customer," widely believed to be the NSA.

After Snowden's disclosures about the extent of US surveillance operations in 2013, the NSA is said to have revised its policies for compromising commercial products. Wyden and other lawmakers have tried to learn more about these policies but they've been stonewalled, according to Reuters.

The NSA also declined to provide backdoor policy details to Reuters, stating that it doesn't share "specific processes and procedures." The news agency says three former senior intelligence officials have confirmed that NSA policy now requires a fallout plan with some form of warning in the event an implanted back door gets discovered and exploited.

The Register asked the NSA to comment. We've not heard back. ®

Get our [9]Tech Resources



[1] https://www.reuters.com/article/us-usa-security-congress-insight-idUSKBN27D1CS

[2] https://www.theregister.com/2020/06/10/congress_juniper_letter/

[3] https://www.theregister.com/2015/12/17/juniper_screen_os_contains_unauthorised_code/

[4] https://cacm.acm.org/magazines/2018/11/232227-where-did-i-leave-my-keys/fulltext

[5] https://www.theregister.com/2015/12/23/juniper_analysis/

[6] https://www.reuters.com/article/us-usa-security-rsa-idUSBRE9BJ1C220131220

[7] https://www.theregister.com/2013/12/23/rsa_nsa_response/

[8] https://www.theregister.com/2015/01/14/nsa_sorry_we_borked_nist_encryption_well_sorry_we_got_caught/

[9] https://whitepapers.theregister.com/

all ears

I'd comment, but then I'd have to kill me.

Maelstorm

LOL. Have a pint on me.

I'd comment ...

Schultz

"NSA policy now requires a fallout plan". So can we take that as confirmation that the NSA systematically subverts encryption in networking gear?

It might be safe to assume that Huawei equipment does not carry NSA back-doors, considering the efforts of the US government to shut down everything Huawei. But then, others might be listening in. I guess you really need strong end-to-end encryption to assume any degree of privacy. And even then, your computer carries a Security and Management Engine / Platform Security Processor, specifically designed to handle sensitive low-level functions. The NSA would not be worth its budget if they didn't find a way into those. Amiright?

How do you avoid US spy gear, it is everywhere.

Anonymous Coward

Intel ME : https://libreboot.org/faq.html#intel

AMD PSP: https://libreboot.org/faq.html#amd

face^H^H^H^Hciabook

everything that google does (google analytics).

Cisco

Apple

Microsoft telemetry (they record everything that your computer runs and does)

Amazon, logs everything, everything, everything (Did you search for something 25 years ago, that is still in the archives).

And then you have the five eyes, which is probably closer to 50 eyes these days.

And then you have the game consoles and Valves Steam, they track and record everything.

And every US company must obey all secret FISA court orders, to carry out the wishes of the NSA.

Who needs backdoors, when they have access to so many front doors.

Re: How do you avoid US spy gear, it is everywhere.

Anonymous Coward

What is the end result of all this you fear?

Just wondering. It all begs the question so what? I'm sure I'll be downvoted off the planet, but I'm talking specifics here. I see no adverts, ever.

Re: How do you avoid US spy gear, it is everywhere.

dak

Microsoft don't record ANYTHING that my computer runs or does.

Nor those of any of my family.

the NSA now claims it can't find the file.

Anonymous Coward

I actually believe that statement.

The NSA is probably too bogged down with the vast amount of data it collects on American citizens to stay in power than to be bothered with dealing with the requsts of an actual ELECTED OFFICIAL like or technically enlighted Ron Wyden.

As a side note on Dual EC..

there is a very informative blog post by a researcher that was having trouble with his WIFI router over the Christmas holidays where he discovered backdoors and ECB in many, many MANY home routers after poking around:

https://github.com/elvanderb/TCP-32764

Re: the NSA now claims it can't find the file.

Maelstorm

Home routers are crap. But it's not in my router. My router is a full computer locked down so tight, Kim Jong Un would be proud.

Hey, can't have that pesky report show up...

Marketing Hack

And complicate the Five Eyes + Japan + India's attempts to create a general encryption backdoor that will never (I repeat--NEVER) get compromised and end up in the hands of crooks or hostile governments.

By long-standing tradition, I take this opportunity to savage other
designers in the thin disguise of good, clean fun.
-- P. J. Plauger, "Computer Language", 1988, April
Fool's column.