4 ms·
Seems like a sensible thing to do, assuming this is a state-level threat actor there’s really no easy way to prove that their contributions are free of back doo
by throwaway63467 3y ago
Seems like a sensible thing to do, assuming this is a state-level threat actor there’s really no easy way to prove that their contributions are free of back doors. Seems not worthwhile risking the security of a large part of the Internet over a few thousand lines of code.
- afc 3y agoBut why would the entire behind this submit all their attacks through the same single identity? Removing all this code could just be removing 1% of their harmful code. How do you deal with the rest? How do you discover the other identities?
- rwmj 3y agoYou start with what you know about, and you investigate other projects carefully at the same time. There's no easy answer here, you do what you can.