In other news, we just learned that any half-decent security agency has already injected their own vulnerabilities and back-doors in OSS.
In other news, we just learned that any half-decent security agency has already injected their own vulnerabilities and back-doors in OSS.
If you do inject vulnerabilities you need to assume your adversaries will find, catalog, and script an exploit for it. And you risk your reputation loss if you do get caught. So I'm sure it has happened, but I bet not that often.
Trust is an important social contract since it lowers the cost of social transactions. But trust takes a long time to earn and can be lost in a flash.
It would be interesting if someone found bad stuff in the kernel, but pet of the org structure makes this hard.
We did not learn that today, but we still assume it.
Btw. the professional agencies have their vulnerabilities injected probably way down in hardware level. Intel ME etc. and or even more bare to the metal.
They got caught and had all their contributions reverted.
Seems like the UMN "researcher" was doing this over and over; the more times you do it, the more likely you are to get caught.