(no title)
freeflight | 2 years ago
Or it would require compromising the server [0]
[0] https://www.csoonline.com/article/3137065/shadow-brokers-lea...
freeflight | 2 years ago
Or it would require compromising the server [0]
[0] https://www.csoonline.com/article/3137065/shadow-brokers-lea...
jchw|2 years ago
Frankly though, I am going to say it; I think the idea that compromising a ton of web servers to be able to build a better profile of a user's web history is part of this UK government surveillance initiative is simply absurd. Compromising servers is a pretty nasty cat and mouse game, especially if you're up against orgs like Cloudflare, Amazon and Google. In practice, there's just no chance this is their strategy.
(And the game certainly isn't going to get any easier. You can, for example, use a TPM to generate your private keys, and have encryption occur on a TPM device, such that extracting them would require much more challenging exploits than just pwning some servers, meaning you'd need to actively have control over the servers to do anything interesting. It's not purely theory, either, though I do not know who is currently using this approach.)
PrimeMcFly|2 years ago
1827163|2 years ago
https://www.asset-intertech.com/resources/blog/2017/12/micro...