Hacker News new | ask | show | jobs
by mikkelewis 2149 days ago
What gives you the low degree of confidence MS engineers couldn't do a complete scan of TikTok's codebase?
1 comments

I don't have confidence about scans in general against novel attacks. Scans are effective against the threat model of off-the-shelf attacks, not a threat model of highly motivated, highly-skilled attackers capable of inserting subtle defects anywhere in a giant codebase.