We've known that EV certs are effectively useless since their debut: research from over a decade consistently shows that users don't know to look for the indicators nor what they mean. Examples: https://t.co/QnpzLnERjx https://t.co/ZOl5lZ2SPB https://t.co
2,926 followers
1,315 followers
@LucaBongiorni @securelyfitz @cybergibbons @LargeCardinal An idea - could it be an embedded CPU backdoor that can be enabled / disabled ? There is a "backdoor=1" mentioned here as a ref. It would be strange to be so obvious to call the environment variable
5,903 followers
RT @2gg: CPU Bugs, CPU Backdoors and Consequences on Security (Loïc Duflot, 2008) http://t.co/b1HOrwF <- CPU can be backdoored? Answer is yes! (Cont)
582 followers
RT @2gg: CPU Bugs, CPU Backdoors and Consequences on Security (Loïc Duflot, 2008) http://t.co/b1HOrwF <- CPU can be backdoored? Answer is yes! (Cont)