Comment by viraptor

3 days ago

> you're worried that the NSA will tap intra-DC traffic but not that it will try to install software or hardware on your hosts

It doesn't have to be one or the other. We've known for over a decade that the traffic between DCs was tapped https://www.theguardian.com/technology/2013/oct/30/google-re... Extending that to intra-DC wouldn't be surprising at all.

Meanwhile backdoored chips and firmware attacks are a constant worry and shouldn't be discounted regardless of the first point.