3 ms·
So all the attack vectors the NSA has used to date are based upon backdoors (voluntary or otherwise) to existing vendors? Something I've been confused and/or m
by Milagre 13y ago
So all the attack vectors the NSA has used to date are based upon backdoors (voluntary or otherwise) to existing vendors?
Something I've been confused and/or mislead about is that if root/CA ssl certificates are compromised, then all derivative ssl certificates are also compromised. Is this true? Are these some of the companies the NSA has 'backdoors' with?
Sorry, I'm not even sure about the terminology here -.-
- kjs3 13y agoYes, what we know is that the NSA has compromised many vendors, including it seems some of the CA vendors. So it's possible that a CA could issue the NSA a certificate that could fool you into thinking an NSA surveillance node was a valid site, or that a bit of software was written by a legitimate vendor and is safe to run. The devil is in the details, of course...if the goal is to have a valid, signed Microsoft key, you really need the Microsoft CA to sign it, but 1) the vast majority of people don't check so close is often good enough, and 2) I personally think Microsoft would cave faster than Verisign, so... And you are correct: if a CA has disclosed their root signing certificate, then the NSA could issue seeming legitimate certificates for pretty much anything.