|
|
|
|
|
by tsimionescu
2051 days ago
|
|
If we're at the level where we think it's an inside job, it doesn't seem that difficult to have 2 people on the inside "reviewing" each other's malicious commits. For what it's worth, my org also has the same policy, but it's intended to catch mistakes, not to protect against malicious actors inside the company. |
|
Imo it’s would be trivial to compromise many. Most companies have soft underbelly units like offshore maintenance engineering, tools teams and patching teams who don’t get a lot of meaningful oversight and can bypass many controls.