Free Republic
Browse · Search
General/Chat
Topics · Post Article

Skip to comments.

NSA suspected in Juniper firewall backdoors
iTnews ^ | Dec 24 2015 10:00AM (AUS) | Staff Writer

Posted on 12/23/2015 9:37:06 PM PST by Utilizer

Dual_EC weaknesses and Juniper error exploited, researchers say.

Security researchers suspect the United States' National Security Agency may have had a hand in the planting of unauthorised backdoors in Juniper's enterprise firewalls.

The network equipment vendor last week issued an urgent security alert for its NetScreen enterprise firewalls, after discovering "unauthorised code" in the device operating system that allows them to be fully compromised.

Juniper had discovered the code during an internal review. The backdoors - which had been in existence since 2012 - meant attackers could gain administrative access and decrypt VPN connections unnoticed.

Researchers have now said the backdoors could have only been planted by a handful of governments due to their sophistication. But it is unclear how the Juniper vulnerability was planted or by whom.

(Excerpt) Read more at itnews.com.au ...


TOPICS: Business/Economy; Computers/Internet
KEYWORDS: firewall; juniper; juniperfirewall; junipernetworks; malware; nsa; security; vpn
Navigation: use the links below to view more comments.
first 1-2021-24 next last
More info on the Juniper problem...
1 posted on 12/23/2015 9:37:06 PM PST by Utilizer
[ Post Reply | Private Reply | View Replies]

To: Utilizer

“NSA suspected in Juniper firewall backdoors”

There’s no doubt about it. I have a friend who quit a Juniper subcontractor that was working on this because he wanted nothing to do with it.


2 posted on 12/23/2015 9:39:49 PM PST by catnipman (Cat Nipman: Vote Republican in 2012 and only be called racist one more time!)
[ Post Reply | Private Reply | To 1 | View Replies]

To: catnipman

And I should have added that Juniper knew what was going on, too.


3 posted on 12/23/2015 9:40:56 PM PST by catnipman (Cat Nipman: Vote Republican in 2012 and only be called racist one more time!)
[ Post Reply | Private Reply | To 2 | View Replies]

To: Utilizer

Details come out after another exploit installed... what do you want to bet?


4 posted on 12/23/2015 9:43:51 PM PST by LowOiL ("Let us do evil that good may come"? ....condemnation is just - Romans 3:8)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Utilizer

Intel, Microsoft and probably Google are also involved.


5 posted on 12/23/2015 9:44:38 PM PST by Zathras
[ Post Reply | Private Reply | To 1 | View Replies]

To: Utilizer

Stasi. They cannot stand anything that the government cannot be allowed to read. UnAmerican.


6 posted on 12/23/2015 9:45:17 PM PST by DesertRhino ("I want those feeble minded asses overthrown,,,")
[ Post Reply | Private Reply | To 1 | View Replies]

To: catnipman

So it’s not just mikrosloth then. Colour Me Surprised (not!).


7 posted on 12/23/2015 9:45:23 PM PST by Utilizer (Bacon A'kbar! - In world today are only peaceful people, and the muzlims trying to kill them)
[ Post Reply | Private Reply | To 2 | View Replies]

To: catnipman

Its interesting that my Intel and Microsoft sources of NSA involvement also are in Colorado.


8 posted on 12/23/2015 9:47:11 PM PST by Zathras
[ Post Reply | Private Reply | To 2 | View Replies]

To: LowOiL

Not willing to bet against that one, mate. Especially after all the news that has begun to pour out in the last several days about this!


9 posted on 12/23/2015 9:47:59 PM PST by Utilizer (Bacon A'kbar! - In world today are only peaceful people, and the muzlims trying to kill them)
[ Post Reply | Private Reply | To 4 | View Replies]

To: Zathras

GMTA, *laugh*!


10 posted on 12/23/2015 9:48:28 PM PST by Utilizer (Bacon A'kbar! - In world today are only peaceful people, and the muzlims trying to kill them)
[ Post Reply | Private Reply | To 5 | View Replies]

To: Utilizer

I know for a fact Intel and Microsoft are involved.
Someone in a Intel staff meeting two years ago said something he shouldn’t have.
Its not on the books, nor is it coming out of Intel’s budget.
The $$$ is coming directly from the Feds.


11 posted on 12/23/2015 9:53:06 PM PST by Zathras
[ Post Reply | Private Reply | To 10 | View Replies]

To: Utilizer
From Wired, http://www.wired.com/2015/12/juniper-networks-hidden-backdoors-show-the-risk-of-government-backdoors/:

Ronald Prins, founder and CTO of Fox-IT, a Dutch security firm, said the patch released by Juniper provides hints about where the master password backdoor is located in the software. By reverse-engineering the firmware on a Juniper firewall, analysts at his company found the password in just six hours.

"Once you know there is a backdoor there, the patch [Juniper released] gives away where to look for [the backdoor] which you can use to log into every [Juniper] device using the Screen OS software," he told WIRED. "We are now capable of logging into all vulnerable firewalls in the same way as the actors [who installed the backdoor]."

Big fun.
12 posted on 12/23/2015 10:14:43 PM PST by TChad
[ Post Reply | Private Reply | To 1 | View Replies]

To: Zathras
I know for a fact Intel and Microsoft are involved.

I don't know about Intel, but from everything I have learned over the years about u-feathers (microsoft) I would not be at all surprised if even more backdoors appear as time goes by.

13 posted on 12/23/2015 10:28:27 PM PST by Utilizer (Bacon A'kbar! - In world today are only peaceful people, and the muzlims trying to kill them)
[ Post Reply | Private Reply | To 11 | View Replies]

To: catnipman
"And I should have added that Juniper knew what was going on, too"

So does Cisco. They just need to be able to say "we didn't know"...they need deniability.

Which begs the question, why did Juniper blow the whistle?

14 posted on 12/23/2015 10:55:55 PM PST by Mariner (War Criminal #18 - Be The Leaderless Resistance)
[ Post Reply | Private Reply | To 3 | View Replies]

To: Mariner
Which begs the question, why did Juniper blow the whistle?

Juniper could have simply released a patch "to resolve security issues" without significantly harming the company's reputation. There is probably a very good reason they didn't do that. Perhaps someone threatened to go public with the details unless Jupiter management did so first.

15 posted on 12/23/2015 11:36:05 PM PST by TChad
[ Post Reply | Private Reply | To 14 | View Replies]

To: TChad

I am behind the times... what is juniper?


16 posted on 12/24/2015 5:17:03 AM PST by Bikkuri ((...))
[ Post Reply | Private Reply | To 12 | View Replies]

To: Bikkuri

They make switches and firewalls for computer networks.

L


17 posted on 12/24/2015 5:19:19 AM PST by Lurker (Violence is rarely the answer. But when it is it is the only answer.)
[ Post Reply | Private Reply | To 16 | View Replies]

To: Utilizer

I worked for Intel for 25 years until a year ago.
It used to be one of the finest companies in the world.
The DOJ/EU threatened it with multi-billion lawsuits unless they did what they were told.

After 911 and .com crash, something happened which changed the direction and it got much worse under Obama.


18 posted on 12/24/2015 8:45:12 AM PST by Zathras
[ Post Reply | Private Reply | To 13 | View Replies]

To: Bikkuri

More info here:

http://freerepublic.com/focus/f-chat/3374008/posts


19 posted on 12/24/2015 12:47:29 PM PST by Utilizer (Bacon A'kbar! - In world today are only peaceful people, and the muzlims trying to kill them)
[ Post Reply | Private Reply | To 16 | View Replies]

To: Bikkuri
what is juniper?

Juniper Networks is a large multinational computer company that makes networking products.

Juniper is the third largest market-share holder overall for routers and switches used by Internet service providers.

https://en.wikipedia.org/wiki/Juniper_Networks

20 posted on 12/24/2015 8:25:13 PM PST by TChad
[ Post Reply | Private Reply | To 16 | View Replies]


Navigation: use the links below to view more comments.
first 1-2021-24 next last

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
General/Chat
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson