3 ms·
Most operating systems already have a "front door" keys in the form of automatic updates certificates. Android, windows, ios, even apt get, all base their secur
by bronzeage 6y ago
Most operating systems already have a "front door" keys in the form of automatic updates certificates. Android, windows, ios, even apt get, all base their security around certificates which, if stolen, can by design lead to running code.
All the objections to end to end encryption + government access fail to mention that we already have an implicit trust in corporate certificates in the security of nearly all devices, and yet that front door was never used by hackers like everyone suggests government backdoors would be used.
- sneak 6y ago> yet that front door was never used by hackers like everyone suggests government backdoors would be used. Would you hear about it if it had? If the US military collaborated with Apple, Google, or Microsoft on a classified project to abuse the autoupdate mechanisms everyone leaves enabled to exec code using their certificates on some military target (leaving aside for the moment that a "military target" is whoever the military says it is and includes people like Snowden), why on Earth do you think that any of the involved parties would ever speak of it? It's reputational poison; everyone would keep that as quiet as humanly possible. We know Apple is willingly collaborating with the FBI to avoid encrypting people's device backups, and that's for domestic traffic as well. They work with the CCP and run special backdoored servers there to be permitted to offer iCloud/iMessage services in China. The Apple software update system can target specific computers by MAC address - fact, today, not speculation. Why do you think it would be known if they offered this sort of assistance? It would likely even be illegal for them to divulge it, for various reasons, depending on how they were asked. FISA spying orders and FBI wiretaps already are.
- bronzeage 6y agoI don't think it'll be known. I bet what you described already happens and yet it attracts far less attention than the end to end encryption shenanigans. I also think WhatsApp messages backup is literally a backdoor to bypass the end to end encryption. I think government RCE is far more serious concern than encryption, yet it gets no attention. We hear about the encryption from all the second class governments that are blocked from the juicy NSA backdoors of auto updates. Ever noticed how the NSA stays quiet in all those encryption debates?
- aesh2Xa1 6y agoWhat do you think of these counter examples? The automatic upgrades channel issue is close to the very heart of, for example, popular browser extensions becoming malicious. Another attack from the past was the system certificate store compromise by Lenovo on workstations and laptops sold to its own customers, allowing for decryption of any HTTPS traffic from the customer. [1] Another high profile attack that everyone will know about is the SolarWinds compromise of its software updates. [2] [1] https://us-cert.cisa.gov/ncas/alerts/TA15-051A https://us-cert.cisa.gov/ncas/alerts/TA15-051A [2] https://www.bleepingcomputer.com/news/security/new-sunspot-malware-found-while-investigating-solarwinds-hack/ https://www.bleepingcomputer.com/news/security/new-sunspot-m...
- simonh 6y agoOn the contrary, certificate breaches are a constant source of issues. https://resources.infosecinstitute.com/topic/cybercrime-exploits-digital-certificates/ https://resources.infosecinstitute.com/topic/cybercrime-expl... There have been cases of breaches at various root CAs, including Adobe products; the Zeus Trojan that had a forged Microsoft certificate; a Dutch government cert breach that impacted Facebook, Twitter, Skype, Google and also intelligence agencies like CIA, Mossad, and MI6; A breach at ANSSI, the French Cyber Security Agency. Then of course there's the recent SolarWinds debacle that should kill this notion once and for all.
- trewnews 6y agoDidn't darknetdiaries do a podcast on how this very thing happened?