Would like to drop this tidbit I found recently. The following is completely unverifiable and not going to convince some people but I found it interesting.
From the AMA linked in the link:
> 1) Security Through Obscurity doesn't work. As mention by /u/Gusec At some point in time, (somebody or some organization) will break this.
When I read that I remembered this:
https://www.reddit.com/r/onions/comments/5i6qa3/can_the_nsaf...
Mirror: http://archive.is/T8yVz
My focus is on the first paragraph in the wall of text, the bit about the signing keys floating around out there.
This is, again, totally unverifiable, and could for all I know be a skiddie strutting (it does read a bit like that). I thought it was an interesting bit of insight though, for what it's worth; and maybe some people could use it as a lead.
Regarding the views offered in that post, I am myself quite wary, simply because I don't know this person's providence and I have no idea if this is whatever you call the opposite of a scare campaign. (If it is it's a bit weird, so it probably isn't.)
(I will note that it looks like the person in question doesn't seem to want to be contactable, so poking them is unlikely to be helpful. I also wonder why they used a new Reddit account for each post.)
I found it when reading https://www.crowdsupply.com/raptor-computing-systems/talos-s... (mirror: http://archive.is/znkp3)