3 ms·
> The USG virtually undoubtedly controls several RSA keys that can be used to sign arbitrary SSL/TLS certificates. Why didn't they just use one of those? aside
by justcommenting 12y ago
> The USG virtually undoubtedly controls several RSA keys that can be used to sign arbitrary SSL/TLS certificates. Why didn't they just use one of those?
aside from the economic cost of "burning" CAs, attribution itself seems to be a consideration, e.g. in other contexts like TAWDRYYARD or LOUDAUTO where "All components are Commercial Off-the-Shelf (COTS) and so are non-attributable to NSA."