nanog mailing list archives
Re: Open source hardware
From: Darren Pilgrim <nanog () bitfreak org>
Date: Fri, 03 Jan 2014 15:49:47 -0800
On 1/3/2014 2:05 AM, Daniël W. Crompton wrote:
Good point Jimmy, there is a world of hurt involved, although it may be slightly less painless when you realize that the alternative is: "*the NSA [who] has modified the firmware of computers and network hardware—including systems shipped by Cisco, Dell, Hewlett-Packard, Huawei, and Juniper Networks—to give its operators both eyes and ears inside the offices the agency has targeted.*"[1]
Why would you think other platforms would be any safer? The NSA plants those bugs with interdiction operations. They could similarly install eavesdroppers in the USB/serial links of your KVM switches and terminal servers and capture your root/admin/console passwords.
Dell, HP, Cisco, etc. were named because the leaked docs mention hardware-specific BIOS/firmware bugging such as ILO piggybacking in a Proliant. I think it's foolhardy believing they wouldn't have similar attacks for just about everything.
Current thread:
- Open source hardware Daniël W . Crompton (Jan 02)
- Re: Open source hardware Faisal Imtiaz (Jan 02)
- Re: Open source hardware Matthew Walster (Jan 02)
- Re: Open source hardware Jorge Amodio (Jan 02)
- Re: Open source hardware Andrew Latham (Jan 02)
- Re: Open source hardware Chris Russell (Jan 02)
- Re: Open source hardware Andrew Duey (Jan 02)
- Re: Open source hardware Jimmy Hess (Jan 02)
- Re: Open source hardware Daniël W . Crompton (Jan 03)
- Re: Open source hardware Darren Pilgrim (Jan 03)
- Re: Open source hardware Arnd Vehling (Jan 03)
- Re: Open source hardware Daniël W . Crompton (Jan 04)
- Re: Open source hardware Arnd Vehling (Jan 05)
- Re: Open source hardware TGLASSEY (Jan 06)
- Re: Open source hardware Andrew Duey (Jan 02)
- Re: Open source hardware Faisal Imtiaz (Jan 02)
- Re: Open source hardware Daniël W . Crompton (Jan 04)
- Re: Open source hardware Ray Soucy (Jan 03)
- RE: Open source hardware Raymond Burkholder (Jan 03)
- Re: Open source hardware Saku Ytti (Jan 03)
- Re: Open source hardware Benno Overeinder (Jan 04)
- Re: Open source hardware Saku Ytti (Jan 04)