Slashdot Mirror


The Juniper VPN Backdoor: Buggy Code With a Dose of Shady NSA Crypto (csoonline.com)

itwbennett writes: Security researchers and crypto experts now believe that a combination of likely malicious third-party modifications and Juniper's own crypto failures are responsible for the recently disclosed backdoor in Juniper NetScreen firewalls. 'To sum up, some hacker or group of hackers noticed an existing backdoor in the Juniper software, which may have been intentional or unintentional — you be the judge!,' Matthew Green, a cryptographer and assistant professor at Johns Hopkins University wrote in a blog post. 'They then piggybacked on top of it to build a backdoor of their own, something they were able to do because all of the hard work had already been done for them. The end result was a period in which someone — maybe a foreign government — was able to decrypt Juniper traffic in the U.S. and around the world. And all because Juniper had already paved the road.'

61 comments

  1. Well, like my papa used to say by penguinoid · · Score: 5, Insightful

    Never attribute to a National Security Letter what can adequately be explained by incompetence. Or was it something else?

    --
    Don't waste your vote! Vote for whoever you want, unless you live in a swing state it won't matter anyways
    1. Re:Well, like my papa used to say by Anonymous Coward · · Score: 0

      How about "Never attribute to incompetence what can adequately be explained by a $10 million dollar check." cf. RSA

    2. Re:Well, like my papa used to say by Anonymous Coward · · Score: 0

      Never attribute to incompetence what can adequately be explained by a National Security Letter.

  2. Well, like James Comey used to say by q4Fry · · Score: 4, Funny

    This isn't a "backdoor," it's an officially sanctioned terrorist detector.

    1. Re:Well, like James Comey used to say by Anonymous Coward · · Score: 0

      Juniper's backdoor has been buggered?

    2. Re:Well, like James Comey used to say by davester666 · · Score: 1

      Hoover just got a boner in his grave.

      --
      Sleep your way to a whiter smile...date a dentist!
  3. End of Juniper by Anonymous Coward · · Score: 2, Insightful

    Good job NSA!

    1. Re:End of Juniper by arth1 · · Score: 1, Insightful

      Not too good. It got caught.

      "someone â" maybe a foreign government"

      Yeeeerright...
      This reeks of CIA and/or Shin Bet.

    2. Re: End of Juniper by Anonymous Coward · · Score: 0

      Kappa?

    3. Re:End of Juniper by Anonymous Coward · · Score: 0

      and of course the first thing the company (aka NSA) wants you to do is update the software to delete all traces of what was on the router

    4. Re:End of Juniper by Rakarra · · Score: 1

      Not necessarily the end. When Hillary or Donald mandate that those backdoors be included on all US networking products, then every networking company will be in Juniper's boat!

  4. This is why by s.petry · · Score: 5, Interesting

    The demands for "Government Backdoor to All Encryption" need to stop! Installing a back door makes it available for _EVERYONE_, not just some agency which may or may not have a warrant. Not that we _will_ see it stop, just that it should.

    --

    -The wise argue that there are few absolutes, the fool argues that there are no probabilities.

    1. Re:This is why by Anonymous Coward · · Score: 1

      This is why it should be called "Buggery code" when backdooring.

    2. Re:This is why by Anonymous Coward · · Score: 0

      The demands for "Government Backdoor to All Encryption" need to stop! Installing a back door makes it available for _EVERYONE_, not just some agency which may or may not have a warrant. Not that we _will_ see it stop, just that it should.

      Nah, they will exclusively put the back door behind a special hardware vpn made by a big company such as Juniper so that only government types have access to it : ;)

      Obvious sarcasm aside, The only plausible way I can think of would be to artificially limit key sizes that a user controls such that the encryption could be broken, and even that is insane, since if you pick a realistic target of say we limit keys to what the NSA can break with big beowulf cluster in a month, then one minor improvement in cryptanalysis could have those keys broken in seconds. Also, I don't believe that anybody pushing for the backdoor would accept such a restriction. They would want near instant access which would mean the bad guys, including major governments, would eventually get near instant access.

      Beyond that, this is where the "if you take away the guns, only the bad guys will have guns" argument actually makes sense. Do you really think any actual terrorists would balk at downloading a decent crypto package, or even simply making their own? It is not as if the code for decent crypto is hard to find...

      On a more serious note, we as a nation need to really stop and think about what we really support. Shall we continue the, "Do anything if it may make us safer." half arsed plan, regardless of the actual costs? Lately major presidential candidates have supported creating religious tests related to citizenship, tourists, and refugees. Are we truly so weak as a country that we will let the terrorist, well, terrorize us to such an extent that we forget our humanity? Government should stay out of religion altogether. Using terrorism as a tactic to do anything is wrong. Those groups must be stopped, and sometimes sadly there are shades of grey in such operations, but that is all the more reason to redouble our efforts at preserving core principles. It is not an easy thing, but it is a necessary thing. At the risk of quoting Harry Potter, it is not uncommon to have to choose between what is right and what is easy. I just wish we would choose the former more often, rather than the later. In some ways the comparison could often be the difference between a well thought out plan and say a sound byte like, "We will build a great and awesome wall and make Mexico pay for it."

  5. This is getting crazy by Anonymous Coward · · Score: 4, Insightful

    This isn't the first excellent post by Matthew Green. His other on ECC was also informative and scary.

    Juniper equipment manages industrial control systems, (like the kind used in nuclear power plants) and we rely on encryption for every part of our online experience - not to mention classified data that presumably protects Americans. The passive collection of VPN data Mr. Green suggests probably happened, and the active exploitation of equipment Snowden revealed by the NSA is a much bigger story than collecting phone records ever was.

    The infosec community making fun of Hillary for suggesting a manhattan project for encryption is funny, but this underlines a serious lack of understanding by too many people in high places.

    1. Re:This is getting crazy by mikael · · Score: 1

      There were several Manhattan projects for the internet. The first was the design of the original network stacks (OSI, DECnet, and many others all replaced by TCP/IP). The second was the http protocol, and the third was the SSL (Secure Socket Layer) that is the basis for encryption for Internet commerce. Unfortunately, that and any other encryption scheme always ended up getting a bit nobbled in places. Probably thousands others if you read the RFC's.

      --
      Vintage computer adverts: http://www.vintageadbrowser.com/computers-and-software-ads
    2. Re:This is getting crazy by Anonymous Coward · · Score: 0

      ... lack of understanding by too many people in high places.

      They understand enough: You're the problem and they will use the law to make you stop being the problem.

    3. Re:This is getting crazy by Anonymous Coward · · Score: 0

      I think it's pretty clear that a project with the goal of creating an encryption standard should NOT be run by any kind of government. The only thing to come out of that is something that doesn't encrypt.

    4. Re:This is getting crazy by Anonymous Coward · · Score: 0

      ... lack of understanding by too many people in high places.

      They understand enough: You're the problem and they will use the law to make you stop being the problem.

      Yes, because we all know what happened with the war on drugs.

      Captcha: Orwellian. (this thing is creepy)

  6. Snowden docs by Anonymous Coward · · Score: 0

    What would be useful right now would be the release of any Snowden docs that might have information about potential NSA/FBI policies that network equipment manufacturers have adopted in order to put backdoors into their products. Those polices would be in the same vein of the backroom deals that printer manufacturers have with the US Secret Service to put hidden codes on printed documents to help trace them back to the printer on which they were produced.

    If there are such docs existing then fuck Glenn Greenwald and the other media gatekeepers from releasing them to the public.

    1. Re:Snowden docs by Anonymous Coward · · Score: 0

      See Project BULLRUN

      Out of all the programs that have been leaked by Edward Snowden, the Bullrun Decryption Program is by far the most expensive. Snowden claims that since 2011, expenses devoted to Bullrun amount to $800 million. The leaked documents reveal that Bullrun seeks to "defeat the encryption used in specific network communication technologies."

      This is speculation, but perhaps one reason the project is so expensive is that it involves payouts to network tech companies to intentionally weaken, or provide backdoors to their products. Kinda like when the NSA paid RSA $10 mil to use a broke cryptography system as a default in their software. http://www.reuters.com/article/us-usa-security-nsa-rsa-idUSBREA2U0TY20140331

      Reuters reported in December that the NSA had paid RSA $10 million to make a now-discredited cryptography system the default in software used by a wide range of Internet and computer security programs. The system, called Dual Elliptic Curve, was a random number generator, but it had a deliberate flaw - or "back door" - that allowed the NSA to crack the encryption.

    2. Re:Snowden docs by AHuxley · · Score: 2

      Crypto experts should have understood this from the 1920's on over every generation of telco and network as a standard given to "other" nations to connect with.
      Every generation has its crypto subverted by 5 eye nations due to location (global capture) and raw computing power to "collect it all".
      US network equipment designers had to fit in domestic production lines around what was Communications Assistance for Law Enforcement Act (CALEA).
      Every big brand device as exported, shipped, designed, upgraded, sold is trap door, back door ready.
      All other nations can do now is design domestically, build and code locally. Suffer the heat, cooling, power, cpu limits and know the domestic code their nation is using is now running on their own hardware. Get out of any import bids for upgrades with a security clause and start designing domestically.
      Allowing, demanding a nation to import any trap door, back door ready "export grade" hardware is really getting strange given all the public crypto news.

      --
      Domestic spying is now "Benign Information Gathering"
    3. Re:Snowden docs by Anonymous Coward · · Score: 1
  7. Criminalize back doors mandate strong encryption. by Anonymous Coward · · Score: 1

    For the good of all internet users and as Internet of Things becomes more prevalent.
    Back doors must be banned and criminalized with severe punishments enacted and strong encryption must be mandated for all devices living on the internet.
    From smart electric meters, household appliances, thermostats, door locks to light bulbs any IoT or other device accessible from the internet all present a risk from malicious actors individuals or nation states.

  8. getting out of hand by danksnugs · · Score: 0, Redundant

    This isn't the first excellent post by Matthew Green. His other on ECC was also informative and scary. Juniper equipment manages industrial control systems, (like the kind used in nuclear power plants) and we rely on encryption for every part of our online experience - not to mention classified data that presumably protects Americans. The passive collection of VPN data Mr. Green suggests probably happened, and the active exploitation of equipment Snowden revealed by the NSA is a much bigger story than collecting phone records ever was. The infosec community making fun of Hillary for suggesting a manhattan project for encryption is funny, but this underlines a serious lack of understanding by too many people in high places. We are shooting ourselves in the foot by letting the NSA hold onto this encryption pipe dream.

    1. Re:getting out of hand by Anonymous Coward · · Score: 0

      Dude, karma whoring? Really?

      http://it.slashdot.org/comments.pl?sid=8523119&cid=51174497

    2. Re: getting out of hand by Anonymous Coward · · Score: 0

      Looking at his user id, it looks like he got high, forgot he posted, and posted it again lol.

  9. "foreign government" by Anonymous Coward · · Score: 0

    already looking to shift the blame onto China or Russia? Hilarious.

  10. Explaining to your Foxnewser Uncle at Xmas dinner by Anonymous Coward · · Score: 0

    So it's like the government wants to put a new lock on all cars so they can easily check to see if a bomb/terrorist is inside. The owner keeps a unique key and in parallel the gov't has a master key that works on all cars. And the gov't keeps that master key nice and safe and sound in their mega-safe vault somewhere underneath Washington DC. Sounds great!

    But what happens if that safe does get broken into by bad guys and the master key is stolen just like in the movies? Sure, if for some reason Bruce Willis gets killed in the first five minutes and can't catch the bad guy they can simply change to a new key for all future cars. But are they going to change the locks on every car that it was already installed on?

    (Pause thoughtfully)

    It's the same exact thing as removing existing security from every car out there. The gov't needs to find a different, more intelligent way to look in car windows to see if there's a bomb/terrorist inside.

    Y'know, face the fact that their job is really hard and do things the old-fashioned way, do their intelligence job using intelligence, not shortcuts.

    Captcha: squirmy

  11. Re:Explaining to your Foxnewser Uncle at Xmas dinn by Anonymous Coward · · Score: 1

    Getting into encryption at the vpn/router level does not really make it easier to catch the bad guys, unless that bad guys actually own the router. Bad guys using encryption are encrypting end to end, not the that level. Maybe I am missing something.

  12. You all should realize... by Anonymous Coward · · Score: 0

    No one seriously wants to try to backdoor all crypto. This is just basic sales 101. They scream "we demand a back door!" for a while, knowing damn well it'll never happen, so that they can work out a "compromise" everyone is much more willing to accept, because hey, at least they aren't going to make EVERYONE do it.

    1. Re:You all should realize... by stooo · · Score: 1

      >> knowing damn well it'll never happen

      Yeah. It just happened. And it's still not properly repaired. (RNG still broken) And that's just the tip of one of the icebergs.

      --
      aaaaaaa
  13. Man, it is incredible by Lisandro · · Score: 3, Interesting

    Judging from what i've read so far it is pretty obvious that the original Dual_EC_DRBG-based backdoor was placed there quite intentionally. Juniper has a lot to answer for.

    1. Re:Man, it is incredible by Anonymous Coward · · Score: 2, Insightful

      RSA was paid $10 million by the NSA to include the broken dual elliptic curve RBG to backdoor their software. I wonder how much Juniper charged for it?

    2. Re:Man, it is incredible by Anonymous Coward · · Score: 0

      Juniper just did what we, the American public, asked them to do. Juniper added a backdoor so we could snoop on our enemies, terrorists, criminals, competitors, and politicians. It was done legally at the governments behest. They shouldn't be crucified for obeying the law. When you get a security letter, you have no choice but to follow it. Please consider this as you write your responses. Also, what better way is there to deal with the chaos in our world than backdoors? Does anyone have a proper answer for this? Inquiring minds want to know. - operator six

    3. Re:Man, it is incredible by Lisandro · · Score: 2

      No. They should be crucified for not disclosing it. Juniper has been selling backdoored security products which, as the article explains, allowed not only the NSA to eavesdrop communications but anyone else as well. RSA took money from the NSA to default that same compromised RNG and never announced it; they should held accountable.

      As for your second question, no. Backdoors are never a proper answer when discussing cryptography, on any form.

    4. Re:Man, it is incredible by houghi · · Score: 1

      I am sure they are willing to do so, but not allowed. You know things are fucked up when the people with the tin foil hats are right.

      --
      Don't fight for your country, if your country does not fight for you.
  14. Re:Explaining to your Foxnewser Uncle at Xmas dinn by mikael · · Score: 3, Informative

    The US government does that with suitcases. You now get to buy suitcases that have a three digit combination lock, as well as a special DHS lock that bypasses that combination lock.

    --
    Vintage computer adverts: http://www.vintageadbrowser.com/computers-and-software-ads
  15. Re:Explaining to your Foxnewser Uncle at Xmas dinn by Streetlight · · Score: 1, Insightful

    The problem with back doors is that they can lie in the software for long periods of time while data theft continues unknown to its owner. Stealing a physical key, stealing a pickup (and sending it to Syria) or car will likely be noticed quickly. And of course, there may be multiple back doors, so swatting down one of them doesn't ensure data security.

    As many writers in these forums have noted, once a back door is installed, anyone, good or bad, with the appropriate tools and skill can open the door. The distinction between bad and good guys seems to be blurred these days.

    --
    In a time of universal deceit, telling the truth is a revolutionary act. George Orwell
  16. Re:Explaining to your Foxnewser Uncle at Xmas dinn by epyT-R · · Score: 1

    If you want to compromise networks carrying sensitive data, you do.

  17. Re:Explaining to your Foxnewser Uncle at Xmas dinn by Sowelu · · Score: 1

    That makes more sense for physical locks. You can reasonably criminalize unauthorized possession of one of those keys, which means if someone commits a crime with one and gets caught, you can nail them to the wall. And because you can't unlock a suitcase from across the planet, it's fairly likely that you can catch someone eventually, and that they'll be in your jurisdiction to actually arrest them.

    Someone in a hostile country gets ahold of a master encryption key? You might never find out, and if you do you can't catch them, and if you catch them you can't prosecute them.

  18. Re:Explaining to your Foxnewser Uncle at Xmas dinn by bytesex · · Score: 1

    That's a service to you. They do that so that your suitcase remains intact. Otherwise, the lock on your suitcase would simply be broken, rendering the locking mechanism useless and the bag ugly.

    --
    Religion is what happens when nature strikes and groupthink goes wrong.
  19. Re: Criminalize back doors mandate strong encrypti by Anonymous Coward · · Score: 0

    Criminalizing things doesn't work at this point... 99.9% of the population is currently implicated in something illegal, with selective enforcement being applied politically. What needs to happen is holding ceo's or owners of corporations personally accountable for their cash cow's actions. Making fines income/profit based could help too. What was it Capone said? I made a million dollars last year and it only cost me 20 grand (regarding tax evasion).

  20. Call me cynical by grasshoppa · · Score: 3, Insightful

    But who's to say this isn't the cover story for the "Government VPN Encryption" program where a foreign entity managed to "steal" the backdoor password so now everyone has to patch.

    Bet we hear similar things from cisco in the coming weeks/months.

    --
    Mod me down with all of your hatred and your journey towards the dark side will be complete!
  21. This is why I bought a 100% free libreCMC router by Anonymous Coward · · Score: 1

    I know what is in it cause we have the complete set of source code and it's actually easy to buid cause it's properly documented and everything. For those who don't know libreCMC is the only real embedded distribution for routers that is 100% free. With other distributions there are non-free parts and even digital restrictions in some cases. Of course most off the shelf routers are non-free and locked now due to FCC rule changes sadly. If your not aware check out ww.savewifi.org

  22. Re:Explaining to your Foxnewser Uncle at Xmas dinn by Anonymous Coward · · Score: 1

    First it is an incredibly simple key the DHS uses, a plastic thing with 3 prongs on it, they have to make thousands one for each DHS/TSA agent.
    People already made copies of it and started stealing things from your bag at the airport.

  23. Re: Explaining to your Foxnewser Uncle at Xmas din by Anonymous Coward · · Score: 1

    A physical key like the TSA one can be duplicated by just having a picture of it. The analogy is actually pretty good here.

    Suspect there's a back door and you'll probably find it. KNOW there's a back door and it really doesn't take so long.

  24. Re:Explaining to your Foxnewser Uncle at Xmas dinn by AK+Marc · · Score: 1

    Or, like real keys, someone opens the lock and reverse engineers the master key. Then every lock is compromised. That's why people panic when root certs have issues. They are essentially master keys to certain types of locks.

  25. Re:Explaining to your Foxnewser Uncle at Xmas dinn by AK+Marc · · Score: 1

    Watch some of the border security shows sometime. They can get into your suitcase without opening the lock, then seal it back like they were never in. Only a keyed hardcase with real latches will keep anyone out. Zippers are secure against someone who doesn't have 5 spare seconds to untraceably open and reseal it.

  26. Malicious code and the firewall .. by nickweller · · Score: 2

    "malicious third-party modifications and Juniper's own crypto failures are responsible for the recently disclosed backdoor in Juniper NetScreen firewalls."

    Given todays computing model, where clicking on a link opens up a two-way connection to a server and executes remote code on your computer, the firewall is next to useless.

  27. OpenSource FTW! by Anonymous Coward · · Score: 0

    We don't need to second guess as to who did what. Open source your code ...

  28. NSA wants a back door to all encryption. by Anonymous Coward · · Score: 1

    Anybody now understand what would happen.

    Retards the lot.

  29. Re:This is why I bought a 100% free libreCMC route by Ambient+Sheep · · Score: 2

    Now you just have to hope that the compiler hasn't got a backdoor generator built into it (the Ken Thompson hack)...

  30. Re: Explaining to your Foxnewser Uncle at Xmas din by Anonymous Coward · · Score: 0

    ... can't unlock a suitcase from across the planet YET.

    FTFY, the IoT disaster will take care of that.

  31. Re: Criminalize back doors mandate strong encrypt by Anonymous Coward · · Score: 0

    How cute. Corporations now ARE the government. They are the de facto rulers, and the State only enforces their will. It's us little people who must watch our every step because we can never know when our benevolent rulers may decide to make an example of us.

  32. How Far... by Anonymous Coward · · Score: 0

    Does the rabbit hole go?

  33. Avoid products of US origin by Anonymous Coward · · Score: 0

    Who knows what pressure the criminal US regime is putting on US companies to allow it to violate citizens civil liberties? It is best to avoid US hardware and software completely, or you will end up paying the price. With a history of economic espionage, I certainly wouldn't be exposing my company to the risk of American spying.

  34. How do we get mainstream press to connect the dots by srijon · · Score: 1

    We need a mainstream front page news article "Government encryption backdoor is exploited by criminals." Instead the mainstream coverage fails to connect the Juniper story to the debate on backdoors at all. e.g. CNN runs with: "Newly discovered hack has US fearing foreign infiltration", an article stoking fears over hackers and cybersecurity without once mentioning the keys put under the mat by the government.

  35. Re: Explaining to your Foxnewser Uncle at Xmas din by Anonymous Coward · · Score: 0

    Hi res photos of the DHS keys were posted on reddit a few months ago.

  36. Re: Explaining to your Foxnewser Uncle at Xmas di by Anonymous Coward · · Score: 0

    If that suitcase was purchased at Walmart, you are an Ubuntu user. Congratulations.