Earlier quoted context omitted.
To make this vulnerable to third parties not physically in control of the hardware (in which case the PCI bus could just be sniffed for the key, or have it grabbed from RAM). Pretty much the only option is side channels. They can't change the algorithm or other NICs that don't offload the encryption/decryption wouldn't be able to successfully decrypt it. They couldn't send "extra" packets with the key somewhere else…
> They couldn't send "extra" packets with the key somewhere else without someone very easily detecting that anomalous traffic not being generated by the system itself. Why would it matter if the traffic is detected? The companies owning the hardware are usually working with the NSA or compelled to do so, so the extra traffic is expected: https://archive.nytimes.com/www.nytimes.com/interactive/2013... You can see part…
What's the point of those down voting comments when there is clearly an evidence that those things happened in the past.