6 ms·
> it enabled it in the first place it took roughly two years including social engineering. I'd say the same approach is much easier in a big software company.
by rigid 2y ago
> it enabled it in the first place
it took roughly two years including social engineering.
I'd say the same approach is much easier in a big software company.
- lazyasciiart 2y agoHow do you mean?
- rigid 2y agoI bet in the majority of cases, there's no need to pressure for merging. In a big company it's much easier to slip it in. Code seemingly less relevant for security is often not reviewed by a lot of people. Also, often people don't really care and just sign it off without a closer look. And when it's merged, no one will ever look at it again, other than with FOSS.
- sylware 2y agoI think you nailed it.
- yborg 2y agoAn insider could just be tasked to look for exploitable vulnerabilities in existing code and compile this information for outside entities without ever having to risk inserting a purpose-made backdoor. Considering the security state of most large codebases, there would be a bottomless well of them.
- 91bananas 2y agoWho wants this job, that is capable of actually doing it properly?
- lodovic 2y agoI've read about workplaces that were compromised with multiple people - they would hire a compromised manager, who would then install one or two developers, and shape the environment for them to prevent discovery, which would make these kind of exploits trivial.
- leeoniya 2y agoso, Office Space?