3 ms·
What would the concrete concern be in this case? Any backdoor would destroy the company brand and be excised immediately in a fork. I suspect they’ll treat it
by gnbfrdjng 9y ago
What would the concrete concern be in this case? Any backdoor would destroy the company brand and be excised immediately in a fork.
I suspect they’ll treat it like a piece of critical infrastructure; their political concerns would be at the gfw level, and I just don’t see the likelihood of weaponized attacks. Databases are usually locked down for egress and any outgoing attempts would be rapidly detected.
- finnh 9y ago> excised immediately Only if the backdoor is obvious. I doubt they would introduce a backdoor that reads `if ($PWD = "supersecretbackdoorpwd") loginAs("root");` But a subtle buffer overrun resulting in a 0day that's only obvious to the writers - that's much more likely. Check out the Underhanded C contest for examples of ways exploits can hide in plain sight. EDIT: I'm not saying that's what going to happen with Alibaba & MariaDb. I'm just saying that "open source" != "free of exploits and backdoors". One of the biggest untruths about open source is that, with enough eyeballs, all bugs are shallow.
- gnbfrdjng 9y agoThe backdoor would either be obvious (ie make outgoing connections) or it would have debatable value (maybe a killswitch?)
- mtgx 9y agoLenovo seems to get caught with a backdoor every 6 months or so lately. Although I do think that has tainted its brand, I think it's still pretty far off from "destroying the brand".
- gnbfrdjng 9y agoLenovo doesn’t make databases.
- srcmap 9y agohttps://www.techpowerup.com/209925/nsa-hides-spying-backdoors-into-hard-drive-firmware https://www.techpowerup.com/209925/nsa-hides-spying-backdoor... This kind of stories doesn't seems to hurt the US HDD maker 's brand, neither. Most of the world just don't care or don't have a choice.