4 ms·
Do you think the presence of a code review practices alone will be enough of a deterrent against agencies using devs for this purpose? Even if you pressure som
by rovyko 8y ago
Do you think the presence of a code review practices alone will be enough of a deterrent against agencies using devs for this purpose?
Even if you pressure someone to make a backdoor and they get caught, you've just exposed your intentions when it could have been easier to go straight to the company.
- 420codebro 8y agoThis. If you are going to go through the effort to compromise key developers, you probably are going to have a team of people grinding on it for him. Eventually you come to him and say "modify this function in this way, and if you get caught, this is your story". Said story would be near perfectly defensible - and at worst case he/she can feign a typo/error and graciously accept someone calling it out and fixing it. Then they just wait a while and attempt again sometime.
- mikerg87 8y agoI don’t think A PR is the only attack vector. I would be suspect of the entire CI/CD pipeline and any production systems or distribution systems in employed
- MrEldritch 8y agoAlso, if I were an Aussie and I'd gotten a request like this, I'd feel pretty incentivized to make the backdoor as blatant and suspicious-looking as possible. The government ordered you to do it; it did not order you to do a good job. So "evil PR" would probably be the easiest thing to catch, and it definitely seems like other compromise vectors are where the real danger is.
- noir_lord 8y agopublic function rot13_GbgnyylAbgNOnpxqbbe() Something subtle like that? Fwiw the UK has near identical legislation and I'm pretty sure the Aussie gov looked at ours first. We lead the world in subtly corrupting democracy.
- zuccs 8y agoWhat if you accidentally cast your coding session to your Twitch stream?