Hacker News new | ask | show | jobs
by gridlockd 2640 days ago
> I mean, it's goofy, hacky, and has obvious security flaws but doesn't look malicious.

Plausible deniability. If you were to implement a backdoor for a company, would you write "professionally done" all over it?

1 comments

So now every bug on a privilege boundary is a backdoor, because of "plausible deniability"?
Did I say that? The point is that it just because it looks like an "honest mistake" doesn't mean it is. If you were to create a backdoor, that's exactly how you'd want to do it.

Given the circumstances, one might wish to err on the side of caution.