Hacker News new | ask | show | jobs
by Latteland 2919 days ago
I am skeptical of source #0. I thought that idea of nsa keys had been debunked. At least that source is not complete. Someone found a string 'nsakey' and they talk about analyzing the 'entropy of the source code'. What does that actually mean in technical terms that make sense to software engineers? I'm too stupid to understand that I guess. Sure, it would make sense for the nsa to try to do this. But it wouldn't make as much sense for microsoft to do it. Linux is out there now. I used to work at microsoft, and our product had a secured special bug database where we recorded security issues. We didn't want random people in the company to know that you could make your login name do string injection was an example of something we had there.