[Return]

Report a post

Preview
>>6291
If by "top-secret exploits" you mean 0days, then yes they do use that for things like CP, although not often. There have been several cases of this in practice. If on the other hand you mean NOBUS 0days, then I imagine those are not used for things like that, though they may still be used to screw over lesser folk. Take for example Tor. Tor uses a few layers of encryption, as well as outer TLS for encryption. This outer TLS used to use dynamically generated DH parameters, but now use static DH parameters (I think originally based on the Apache params). Due to the fact that, if a DH key modulus is attacked and broken, all recorded key exchanges can then be broken, despite forward secrecy. An example of NOBUS might be the ability to precompute a 1024 bit DH modulus attack and use it against something like Tor, breaking the outer TLS layer and being able to mount much more effective traffic correlation attacks. Information gained from that can then be given as a tip to the FBI (it happens), and the end result is that the little guys get screwed over by an extremely powerful attack like DH precomputation that is otherwise impossible to achieve, without FVEY/SSEUR revealing their capabilities in any way.
Post number No.6320
Board Discussion
Optional. Describe what's wrong with it.