|
|
|
|
|
by jwcrux
2051 days ago
|
|
So there are two things to consider here: 1) The “observable window” is the entire installation time. If they make installs take forever, that’ll affect everyone which should raise alarms pretty quick. 2) The conditional execution is possible but the installation is done using a vanilla alpine container which will match many legitimate hosts too. And any fingerprinting activities that involve syscalls would be detected in the process. All this to say, there’s always room to continue raising the bar! |
|