It's 5 for not doing it and 5 for telling anyone, 10 for both
It's 5 for not doing it and 5 for telling anyone, 10 for both
And there have to be limitations as to how far an individual could go as to subterfuge, so if your company enforces a 2-person code review and there aren't other authorized Australian nationals at hand, you could point at process preventing you from doing so without others' knowledge (how naive this defense is, I have no idea)
1. you take job at place with code review.
2. Australian police say place a backdoor.
3. You say we have code review the backdoor will be caught.
Now at this point the following might happen.
4a. make sure your code is reviewed by X. 4b. ok I guess it won't work. 4c. here is the code to put in, it has a very hard to catch bug that we can exploit.
in no way would I expect them to say 4d. well we're going to take you to court because you took a job that makes entering backdoors difficult.
on edit: improved formatting on 2nd edit: I removed the leading No but, because I can't remember why I started off with that.
Or even a reason? I mean, unless the backdoor has a hard-coded URL like `www.ThisIsAGovernmentBackdoor.gov.au`, then a backdoor wouldn't seem to automatically implicate the government. Then an employer might well assume that the employee is just doing their own hacking. And presumably the employee can't say otherwise, right?
Or does the law say that employees can refuse if they fear discovery? And if so, couldn't employees always just refuse on that basis?
If their purpose is to hack company X, are informed that the way they intend to do it will be discovered and expose the tool they were going to use, then I expect they would refrain from doing that and try to find some other way. If they do not refrain then their purpose must not be to hack company X but really just to expose the tool for some reason.
However if they just say I will likely be discovered because of this reason, the police will probably just say "that's a risk we're willing to take!" and go for it.
I suppose Australia can attempt to make a law saying any company based in Australia or selling products in Australia or with an internet presence available inside the country of Australia must stop using code review in case you ever hire an Australian citizen we want to put backdoors in your code.
Just imagining it is giving me quite the entertainment value.
> The Underhanded C Contest is an annual contest to write innocent-looking C code implementing malicious behavior. In this contest you must write C code that is as readable, clear, innocent and straightforward as possible, and yet it must fail to perform at its apparent function. To be more specific, it should perform some specific underhanded task that will not be detected by examining the source code.
Even knowing there is an exploit in the code, I probably would never be able to find most of them. My favorite is 2008's winner who's goal is to write a redaction program to redact text. It doesn't use any buffer/array hacks, the code is very straightforward and simple and small, and it would work in languages other than C. It's a terrifying example of how easy it is to write malicious code that would pass multiple code reviews but still has a backdoor!