5 ms·
BGR logic strikes again. There is a world of difference between a backdoor and an exploit... Neither is desirable but one can at least be secured by a key or s
by bostand 9y ago
BGR logic strikes again. There is a world of difference between a backdoor and an exploit...
Neither is desirable but one can at least be secured by a key or something.
- mcphage 9y ago> one can at least be secured by a key or something Which can be leaked.
- kardos 9y agoA hoarded vulnerability and a hoarded backdoor key are difficult to distinguish is this context, ie, leaking of either results in the same catastrophe.
- ikeboy 9y agoApple already has a backdoor key which they use every single time any iOS device needs to update. The FBI wasn't asking for the key, they were asking for the key to be used to sign one update. That signature would inherently have only worked once, as it includes a nonce and device ID.
- wlesieutre 9y agoIf the NSA let its hacking toolkit leak, what makes you think they can keep a backdoor key 100% secure for eternity?
- gutnor 9y agoAnd how many keys has been done ? Once a company accepts to develop backdoor to operate in the US, what guarantee do you have they have no similar arrangement with other governments ? Patriotism ? That's a dangerous currency to use with global companies.
- simonh 9y agoIt's not even got anything to do with patriotism. If the US government can legally mandate companies to put back doors in devices in US markets, then foreign governments can mandate the same in their markets. Of course they could anyway, but the US and other western governments should be setting a principled example here and diligently pressuring other governments to adhere to the same standards.
- geofft 9y agoSecured by a key, you say? Like one of these? https://prod01-cdn05.cdn.firstlook.org/wp-uploads/sites/1/2015/09/TSA-2-article-header.jpg https://prod01-cdn05.cdn.firstlook.org/wp-uploads/sites/1/20...
- sdca 9y agoI agree with you on all points besides securing with a key being somehow a more desirable trait to a backdoor. Keys can leak(such as TSA checked baggage master keys) or authentication could be bypassed(such as Intel ME). BGR is simply virtue signalling against the feds when it comes to comparing the "virus of the day" with a hypothetical data recovery method that would only be available in an offline forensics lab setting with no viral attributes. WannaCry is much more Microsoft's fault than the feds or Wikileaks.