| ▲ | johnsmith1840 4 hours ago | |
Side channel is academic at best. Watching memory changing on a complex code base without having said code base is near impossible. 1. Run code 2. Watch memory changes 3. Correlate those to real data If your code is doing anything complicated that's an intense thing to determine. If you're deep enough for a side channel there's likely a lot easier way of getting in. | ||
| ▲ | SepiaSapient 3 hours ago | parent [-] | |
Brainfart on my part. I was referring to what @majorchord was worrying about, the unencrypted messages in the client get exfiltrated and get sent to the spooks using steganography on some benign request, edited my comment. My mental model is that most competent intelligence agencies have a PRISM 3.0 deal with FAANG, including on E2E products or at least have devs on the payroll. I imagine that any backdoor is only used on important targets, so no intel sharing with Cletus the deputy. | ||