Earlier quoted context omitted.
There were a bunch of Google engineers who worked through Christmas that year who sure we're pretty pissed off about the unexpected work and were furious at the NSA.
Of course. Most Google engineers would not be involved in it, and would of course be doing their best to keep Google's customers' data secure.
Jeff Bezos's phone 'hacked by Saudi crown prince'
321–327 of 327 posts
Re: Jeff Bezos's phone 'hacked by Saudi crown prince'
#322Re: Jeff Bezos's phone 'hacked by Saudi crown prince'
#323Earlier quoted context omitted.
Exactly what is your point? Durov is talking about Signal, not some hypothetical application you came up with to leak keys.
Wasn't he talking about WhatsApp that integrates Signal protocol? Asking if integrating protocol allows the "host" app to leak keys is completely valid.
Open source vs closed source is not meaningful here.
Re: Jeff Bezos's phone 'hacked by Saudi crown prince'
#324Earlier quoted context omitted.
My point specifically is that by increasing build and deployment security. You actually are decreasing the amount of people who can potentially review and audit the build. Thus making it more likely that someone in power could introduce a backdoor that nobody else in the large org knows about.
I don't think that's true? Increasing build security is about limited the number of folks who can modify the process. That's orthogonal to auditability.
I'd also say it's not completely unrelated. Let's consider a hidden build machine process. Once you've hidden that, preventing modifications to the build process by people "not in the know" makes it much less likely that said process can be discovered (either on purpose or accident) If everyone can and does have full access to those build machines it increases the likelihood that someone making a modification could run into said process.
Re: Jeff Bezos's phone 'hacked by Saudi crown prince'
#325Earlier quoted context omitted.
Wasn't he talking about WhatsApp that integrates Signal protocol? Asking if integrating protocol allows the "host" app to leak keys is completely valid.
Again, reading bytecode is not hard. Even reading decompiled binaries isn't very hard. If WhatsApp was leaking keys on the side it wouldn't be too difficult to find, especially given how incredibly high profile it is as a target. Open source vs closed source is not meaningful here.
Re: Jeff Bezos's phone 'hacked by Saudi crown prince'
#326Earlier quoted context omitted.
I shudder to think what would have happened if Obama had ultimately refused to give up his personal phone, and every half-talented hacking group on the planet had pwned it six ways from Sunday—what a national security disaster that would have been! Oh wait
The Clinton server wasn't really interesting because she broke the rules...it was because the Chinese/whomever could grab stuff and the owners had plausible deniability.
Re: Jeff Bezos's phone 'hacked by Saudi crown prince'
#327Earlier quoted context omitted.
>If you aren't a high profile target, you may not be worthy of being targeted specifically. That's what I am questioning. There are many sysadmins, key executives in tech companies, or open source contributors who may not be "high profile" in the traditional sense but be juicy targets. Arguably there are more useful targets to hack than a CEO who's assuming their every move is being studied and always keeps truly sen…
Some CEOs have “cube” as their password and got their company hacked. Please don’t say who, but it happens.