Hacker News new | ask | show | jobs
by mtgx 3025 days ago
Maybe because Juniper loves those Cisco backdoors, too.

Back in 2015 they pretended to be shocked that the Dual_EC algorithm, of which people warned it may contain a backdoor since 2007, and then it was confirmed by Snowden's documents in 2013, could actually be exploited by the baddies.

2 comments

> Back in 2015 Juniper pretended to be shocked that the Dual_EC algorithm

To complete your point:

Security researchers solved the mystery around a sophisticated backdoor embedded in Juniper firewalls. Juniper Networks announced on [Dec. 17, 2015] that it had discovered two unauthorized backdoors in its firewalls, including one that allows the attackers to decrypt protected traffic passing through Juniper's devices. The NSA may be responsible for that backdoor. Even if the NSA did not plant the backdoor in the company's source code, the spy agency may in fact be indirectly responsible [due to] weaknesses the NSA allegedly placed in a government-approved encryption algorithm known as Dual_EC. The Juniper backdoor is a textbook example of how someone can exploit the existing weaknesses in the Dual_EC algorithm the security community warned about back in 2007.[1]

[1] Paraphrased from https://www.wired.com/2015/12/researchers-solve-the-juniper-...

IMHO, the dual EC thing, as bad as it was, is completely different than the sloppy crap like a litany of hard coded passwords. One of these things has political complications, albeit ones that should not matter, and the other is an issue of basic engineering competence.