So all the attack vectors the NSA has used to date are based upon backdoors (voluntary or otherwise) to existing vendors?
Something I've been confused and/or mislead about is that if root/CA ssl certificates are compromised, then all derivative ssl certificates are also compromised. Is this true? Are these some of the companies the NSA has 'backdoors' with?
Sorry, I'm not even sure about the terminology here -.-