Skip to main content


Once again, for the people in the back: we don't build back doors because there is no way to build a back door that only good guys can walk through, motherfuckers.

wsj.com/tech/cybersecurity/u-s…

in reply to evacide

This seems like a massive own-goal for the US intel community.
in reply to klausfiend

@klausfiend If you are interested in more like this, I recommend "Spyfail" by the esteemed IC historian James Bamford.
in reply to evacide

brain tried to coerce this into the form of “we don’t do this because it’s easy…” and I couldn’t square it because you (specifically and especially) are obviously not making an excuse for backdooring software.
in reply to evacide

I recently had to explain to an Eng leader that when I was saying “not possible”, I did not mean, “we can do it if we’re clever enough”.
in reply to evacide

Trying to create a back door for 'good guys' is like saying you’ll only let the nice sharks in the pool.
Unknown parent

mastodon - Link to source
evacide
@ErictheCerise Oh they are not, but the people who insist that backdoors will be fine all believe they are the good guys or they are making them for the good guys.
in reply to evacide

My vocabulary is no longer rich enough to discuss this topic without getting very sweary.
in reply to evacide

have we tried asking our adversaries not to use our backdoors?
in reply to evacide

But the sign clearly said "Employees Only" and we never anticipated the kind of lunatic who'd ignore that kind of warning!
in reply to evacide

Apple came pretty close, though. Their M1 backdoor appeared less than 1 year after the FBI dropped their All Writs case. And it required a magic key to start the exploit chain, which they figured no one could find. Until Kaspersky did.

To their credit, they had the disabling code ready to go, so when it was discovered they claimed "bug" and pushed the "off" button.

in reply to evacide

I like the use of motherfucker there...wait a second. 😂

Yeah, a "backdoor" is just a vulnerability.

in reply to evacide

how are we still having this conversation in 2024? 🙁
in reply to evacide

- my usual comment is that good-guy-only backdoors are like good-guy-only holes in body armour.
in reply to evacide

it's simple, just make someone pinky promise that they're not going to use the backdoor for evil. Everyone knows bad guys don't pinky promise.
in reply to evacide

we'll just put the backdoor in the same vault they kept the CSS DVD key. Sorted.

This website uses cookies. If you continue browsing this website, you agree to the usage of cookies.