3 ms·
Check this for example: https://www.zdnet.com/article/cisco-removed-its-seventh-backdoor-account-this-year-and-thats-a-good-thing/ https://www.zdnet.com/article
by _8j50 3y ago
Check this for example: https://www.zdnet.com/article/cisco-removed-its-seventh-backdoor-account-this-year-and-thats-a-good-thing/ https://www.zdnet.com/article/cisco-removed-its-seventh-back...
It's not always obvious but devs adding backdoors and vulns is not all that new.
The guy may have been anonymous here but a legit dev's github account compromise could lead to the same outcome.
Each open source project decides how much vetting is applied to contributors. I don't think you can contribute to Linux without using your real name and email for example. In some countries, getting a job for the express purpose of sabotage is very common. People using stolen id's to get remote dev job's is also a thing (although I haven't heard that being abused for backdooring). At least with open source, you can audit the code for anonymous user contributions and look at their policy for it.