Cyber Monday Deal: Up to 60% off InvestingProCLAIM SALE

Congress seeks answers on Juniper Networks breach amid encryption fight

Published 06/10/2020, 10:39 AM
Updated 06/10/2020, 02:15 PM
© Reuters. The Senate Finance Committee holds hearing on role of unemployment insurance during coronavirus pandemic in Washington
JNPR
-
META
-

By Joseph Menn

SAN FRANCISCO (Reuters) - A group of U.S. lawmakers preparing to fight a legislative attack on encrypted communications is trying to establish what happened when encryption was subverted at a Silicon Valley maker of networking gear.

Democrat Ron Wyden, who sits on the Senate Intelligence Committee, said the 2015 incident at Sunnyvale-based Juniper Networks (NYSE:JNPR) could shed light on the risks of compromised encryption before an expected hearing on the proposed legislation.

The EARN IT Act could penalize companies that offer security that law enforcement can't easily penetrate.

"Attorney General (William) Barr is demanding that companies like Facebook (NASDAQ:FB) weaken their encryption to allow the Department of Justice to monitor users' conversations," Wyden told Reuters.

"Congress and the American people must understand the serious national security risks associated with weakening the encryption that protects Americans' personal data, as well as government and corporate systems."

In a letter to Juniper Chief Executive Rami Rahim sent late Tuesday, Wyden, Republican Senator Mike Lee of the Judiciary Committee, and the chairmen of the House Judiciary and Homeland Security committees asked what had happened to an investigation Juniper announced after it found "unauthorized code" inside its widely used NetScreen security software in 2015.

Soon after, reseachers discovered the code in question had changed one part of a security mechanism secretly designed by the National Security Agency and widely believed to contain a back door for spying, known as Dual Elliptic Curve.

Juniper included the NSA technology before its exposure in the wake of Edward Snowden's leaks about the agency's method. Some time later, insiders or outside hackers switched the key https://www.reuters.com/article/us-spying-juniper-idUSKBN0UN07520160109 to the back door, giving access to user traffic.

The FBI launched an investigation https://www.reuters.com/article/us-juniper-networks-cyberattack-idUSKBN0U12P420151219 that was never publicly resolved.

Juniper did not respond to a request for comment on the letter or the status of its investigation.

Many questions remain, including why the company adopted the technology, what U.S. spies were able to glean through it, and how many U.S. government and commercial customers were monitored in the second round of espionage.

© Reuters. The Senate Finance Committee holds hearing on role of unemployment insurance during coronavirus pandemic in Washington

"Juniper’s experiences can provide a valuable case study about the dangers of back doors, as well as the apparent ease with which government back doors can be covertly subverted by a sophisticated actor," the elected officials wrote to Juniper.

Latest comments

Risk Disclosure: Trading in financial instruments and/or cryptocurrencies involves high risks including the risk of losing some, or all, of your investment amount, and may not be suitable for all investors. Prices of cryptocurrencies are extremely volatile and may be affected by external factors such as financial, regulatory or political events. Trading on margin increases the financial risks.
Before deciding to trade in financial instrument or cryptocurrencies you should be fully informed of the risks and costs associated with trading the financial markets, carefully consider your investment objectives, level of experience, and risk appetite, and seek professional advice where needed.
Fusion Media would like to remind you that the data contained in this website is not necessarily real-time nor accurate. The data and prices on the website are not necessarily provided by any market or exchange, but may be provided by market makers, and so prices may not be accurate and may differ from the actual price at any given market, meaning prices are indicative and not appropriate for trading purposes. Fusion Media and any provider of the data contained in this website will not accept liability for any loss or damage as a result of your trading, or your reliance on the information contained within this website.
It is prohibited to use, store, reproduce, display, modify, transmit or distribute the data contained in this website without the explicit prior written permission of Fusion Media and/or the data provider. All intellectual property rights are reserved by the providers and/or the exchange providing the data contained in this website.
Fusion Media may be compensated by the advertisers that appear on the website, based on your interaction with the advertisements or advertisers.
© 2007-2024 - Fusion Media Limited. All Rights Reserved.