What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Bloomberg News’s September 2, 2021 investigation added detail to the 2015 Juniper Networks breach: sources told the outlet that the U.S. Department of Defense had pressed Juniper to include a controversial random-number generator in NetScreen devices, while Juniper investigators reportedly attributed two later changes to a group identified as APT 5. That reporting did not establish that the NSA directed or exploited the breach. Its knowledge of the weakness, the full scope of customer impact, and the number of devices actually exploited remain publicly unresolved in the cited accounts.

What happened in the Juniper breach?

In December 2015, Juniper disclosed unauthorized code in ScreenOS, the software used by its NetScreen products. The issue was more than a report of stolen source code: the company said code changes could affect the security of devices in customers’ hands. Bloomberg’s account of Juniper’s investigation described two distinct mechanisms—a change to a cryptographic random-number generator and a separate master-password backdoor.

Juniper urged users to install an update “with the highest priority,” as Bloomberg quoted the company’s December 2015 disclosure. That warning reflected the seriousness of the exposure, but it does not establish how many customers were successfully monitored or how many devices attackers accessed.

What did the 2021 reporting add about a U.S. role?

Bloomberg reported, based on interviews with a former senior U.S. intelligence official and Juniper employees involved in or briefed on the decision and investigation, that Juniper began including Dual_EC_DRBG in NetScreen devices in 2008 after Department of Defense pressure tied to future military and intelligence contracts. Some Juniper engineers reportedly had concerns about the algorithm. The Pentagon declined to discuss its relationship with Juniper.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

This is an account attributed to Bloomberg’s sources, not a formally documented government finding. It describes alleged pressure to include the algorithm; it does not establish that the Defense Department ordered a malicious alteration to Juniper’s products. Nor does it answer whether the NSA knew about, requested, or used any weakness. Bloomberg reported that the NSA declined to comment.

How the reported changes differed

The reporting describes two separate changes with different potential consequences. Juniper’s investigators reportedly attributed both to APT 5, drawing on people involved in the investigation and an internal document reviewed by Bloomberg. That is reported attribution, not a finding in a court judgment.

Rank #2
Sale
Juniper SRX340 16-Port Security Services Gateway Appliance (Renewed)
  • Juniper SRX340 Router - 8 Ports - Management Port - 12 Slots - Gigabit Ethernet - 1U - Rack-mountable
Reported change Potential access enabled What the reporting establishes
2012 change to the Q value in Dual_EC_DRBG Could potentially let an attacker who knew the relevant secret relationship decipher encrypted data carried over NetScreen VPN connections. Bloomberg said Juniper investigation sources and an internal document attributed the change to APT 5. The report describes a capability; it does not prove that every exposed customer’s communications were decrypted.
2014 master-password backdoor, reportedly disguised as debugging code Could permit direct access to NetScreen devices; Bloomberg reported that a skilled attacker could delete evidence of use. Bloomberg said Juniper investigation sources and an internal document attributed this separate change to APT 5. The cited accounts do not provide a verified count of devices accessed.

What is Dual_EC_DRBG, and why did its Q value matter?

Dual_EC_DRBG is a deterministic random bit generator: software that produces a sequence of values intended to be unpredictable and used in cryptographic systems. Its security controversy centers on the choice of a public parameter called Q. Bloomberg reported that Microsoft researchers had published a technical warning in 2007: whoever selected Q could, if they knew a hidden mathematical relationship used to construct it, potentially calculate secret key material and decrypt communications.

The risk was not simply that Juniper used a named algorithm. In Bloomberg’s account, the 2012 change to Q was what reportedly let the later attacker exploit the weakness in Juniper’s implementation. A potentially exploitable design does not itself prove that a particular actor had the necessary secret, that every affected connection was decrypted, or that a customer was targeted.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Timeline of the breach and public scrutiny

Date What the cited accounts say
2007 Microsoft researchers published a warning about the potential consequences of how Dual_EC_DRBG’s Q value was chosen, according to Bloomberg.
2008 onward Bloomberg’s sources said Juniper began including Dual_EC_DRBG in NetScreen devices after Defense Department pressure linked to future contracts. The Pentagon declined to discuss its relationship with Juniper.
2012 Juniper investigation sources and an internal document reportedly attributed a change to the algorithm’s Q value to APT 5.
2014 The same reporting said investigators attributed a separate master-password backdoor to APT 5.
December 2015 Juniper disclosed unauthorized code in ScreenOS. Senator Ron Wyden’s later congressional release described malicious code in software updates and products delivered to customers.
2018 Wyden’s release said NSA officials told his staff about a “lessons learned” report concerning Dual_EC_DRBG. His office said it repeatedly requested the report and that the NSA later asserted it could not locate it.
January 29, 2021 Wyden, Senator Cory Booker, and House members publicly asked the NSA questions about Juniper, SolarWinds, Dual_EC_DRBG, NSA’s knowledge, and any request that Juniper include the algorithm.
September 2, 2021 Bloomberg published its investigative reconstruction, including the alleged Defense Department role and the reported APT 5 attribution.

What did lawmakers ask the NSA, and what is known about the answers?

The January 29, 2021 release from Wyden’s office documents oversight questions, not proof of the premises behind them. The lawmakers asked about the NSA’s actions after the 2015 disclosure, its knowledge of the suspected weakness, how Q was selected, and whether it asked Juniper to include Dual_EC_DRBG or other standards. They also raised the reported “lessons learned” report that the NSA later said it could not locate.

Wyden said, “I am extremely disappointed that the NSA refused to answer my questions about their reported role in the Juniper affair,” as Bloomberg quoted him. The lawmakers’ letter, quoted in Wyden’s release, said: “The American people have a right to know why NSA did not act after the Juniper hack to protect the government from the serious threat posed by supply chain hacks.” These statements convey the lawmakers’ concern; they do not supply the NSA’s answers or independently establish that the NSA directed an intrusion.

Rank #4
Sale
Juniper Networks SRX300 Services Firewall Gateway Security Appliance w/ AC Adapter [No Rack Kit] (Renewed)
  • Item Package Quantity - 1
  • Product Type - NETWORKING ROUTER
  • Memory - 4000. GB
  • Accessories may not be original, but will be compatible and fully functional. Product may come in generic box.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What remains unresolved?

  • NSA knowledge or involvement: The cited reporting does not determine what the NSA knew, whether it asked Juniper to include Dual_EC_DRBG, or whether it took any action to insert or exploit a weakness in Juniper products.
  • Customer impact: The cited accounts do not establish a verified number of customers or devices successfully monitored, or prove that all potentially exposed devices were exploited.
  • Attribution: The APT 5 attribution is what Bloomberg reported from Juniper investigation sources and an internal document. It is not presented here as a court finding.
  • Scope of compromise: The cited accounts do not settle the full scope of the breach or identify every party that may have known about the original algorithm weakness.

The clearest distinction is between the reported pressure to adopt an algorithm and the reported later tampering with Juniper’s implementation. Bloomberg’s investigation connected the first to alleged Defense Department contract pressure and attributed the two changes to APT 5. It did not resolve the NSA’s role or establish how many customers were compromised.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.