3 ms·
I stopped reading after: All your suggestion does is, it adds a layer or two where we hope the NSA doesn't compromise them in case you'd want to use that chain
by bumholio 8y ago
I stopped reading after:
All your suggestion does is, it adds a layer or two where we hope the NSA doesn't compromise them in case you'd want to use that chain to install and validate Signal.
You can't possibly think that compromising the full infrastructure of MIT or F-Droid, a noisy criminal act with serious repercussions against the perpetrators, is in any way comparable to a MITM against a suspect.
That's like saying "Ok, North Korea has some small nukes, but if they really want to get serious about a nuclear attack, they can always penetrate the White House and steal the nuclear football from under Trump's ass".
- tabletopneedle 8y agoYou can't possibly say one needs to compromise MIT's entire infrastructure when all it needs is MITM attacks against the browsing session. That doesn't require compromising either if you have a CA private key the client's browser trusts. Only if there is certificate pinning do you need the server's key, and even at that case you only need to compromise the private key of the university. You don't have to compromise every system to do that. Compromising only a single system among the small group of systems that hold the private key will do. Your comparison is as thoughtless as the rest of your reply.