|
|
|
|
|
by whizzter
1297 days ago
|
|
1: Hopefully the delay was so the device updates with time-based activation triggers would shut out the bad actor in as many places as possible at once. 2: I don't see any reason to share the master key with an OEM, the master key could be used to sign certificates down-chain but they should never share it. This leaves 2 options: - Google had waaay too sloppy key management (sitting on servers or even possibly developer laptops) - Google had proper management by putting the keys on HSMs or some virtual HSM with multi-party activation, unless there was weaknesses in the HSMs(or the virtual HSM OS) then yes, some person(s) would've gained physical access to extract it. 3: Universal 2nd stage rootkit? |
|