8 ms·
This is what's really concerning. If FSB was able to actually implement something and shell all nginx boxes (and thusly obtain SSL certs, intercept communicatio
by anonymousjunior 7y ago
This is what's really concerning. If FSB was able to actually implement something and shell all nginx boxes (and thusly obtain SSL certs, intercept communications, etc..) imagine how much access they'd have.
- account73466 7y agoThen they would definitely advertise it by attacking the company so that the whole world would know about their secret backdoor. Very smart, indeed!
- true_religion 7y agoJust thinking about it would have a chilling effect which to the authorities may be better than actual access.
- Filligree 7y agoI'm going to switch from nginx to Caddy, so I guess?
- kick 7y agoPhysical access is easier to get than remote access when you have a baton and the intelligence of a cop.
- dsl 7y agoFSB/GRU are more than just thugs with batons, they are professionals who could easily slip in to a building at night and access computers without anyone knowing. Basically the Russian CIA.
- golergka 7y agoGRU have been severely embarrassed quite a few times in the last few years. It does seem that they're much closer to thugs with batons.
- penagwin 7y agoOn the flip side I feel like nginx has too high of a profile. It'd be better to target some other low level system package or npm/pip module, etc.
- stjohnswarts 7y agothat's not going to happen, too many security experts constantly monitoring nginx. That's the beauty of it being a high profile open source project.
- auiya 7y agoYeah? https://en.wikipedia.org/wiki/Kleptography https://en.wikipedia.org/wiki/Kleptography https://en.wikipedia.org/wiki/Heartbleed https://en.wikipedia.org/wiki/Heartbleed https://en.wikipedia.org/wiki/Shellshock_%28software_bug%29 https://en.wikipedia.org/wiki/Shellshock_%28software_bug%29 https://www.computerweekly.com/news/252473363/EU-patches-20-year-old-open-source-vulnerability https://www.computerweekly.com/news/252473363/EU-patches-20-... https://en.wikipedia.org/wiki/Dual_EC_DRBG https://en.wikipedia.org/wiki/Dual_EC_DRBG
- TheRealDunkirk 7y ago"I keep track of these things, Clark. One of us has to."
- oefrha 7y agoJust like too many security experts monitoring crypto standards so NIST wouldn’t try to slip in a backdoor?
- lawnchair_larry 7y agoNo, not similar. Crypto is very different.