Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

"At this point, the odds are close to one that every target has had its private keys extracted by multiple intelligence agencies" Any proof of this?


It's bullshit.

I'm 100% positive that many targets have had their keys extracted, but it's hard-to-impossible for the attacker to choose what fragment of memory the server returns, and it depends heavily on the server in question. What works against nginx won't work against lighttpd or apache.

I hit a site I control repeatedly yesterday and couldn't even get any common byte-arrays in common across hundreds of connections.

Of course, as good practice, all organizations should treat their keys as compromised and issue new ones.

Also, his "it leaves no trace" is a problem. It's trivial to recognize the traffic pattern.


If it was your sole purpose in life to bust dams, and then suddenly you were given a cache of unlimited dynamite...what would you do?

To the point, when the nature of a thing is to foo and you remove all obstacles from that event, expect positive feedback...and lots of it.


Well the odds are non-zero. If you're worried about intelligence agencies harvesting your private keys, any odds above 0 is close to 1.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: