4 ms·
If it was a genuine "backdoor" why would you want use a publicly available key?
by fungi 7y ago
If it was a genuine "backdoor" why would you want use a publicly available key?
- anxman 7y agoThis isn't a backdoor but it is a major vulnerability.
- MaulingMonkey 7y agoBeing the only keyholder reduces plausable deniability, so maybe.
- RL_Quine 7y agoThe private key is on the shipped devices, from my reading.
- MaulingMonkey 7y agoAgreed. I'm hypothesizing that you might do this, even with keys intended to be used as a back door, by shipping it on devices, you vastly increase the number of potential suspects for any backdoor abuse. Continuing this train of thought - a hardcoded password is classic example of a backdoor, and just as "public" as including a private key.