Hacker News new | ask | show | jobs
by tveita 808 days ago
Notably that was a "no-one-but-us" backdoor, that requires a specific secret key to exploit. We'll see when someone analyzes the payload further, but presumably this backdoor also triggers on a specific private key. If not there are ways to do it that would look far more like an innocent mistake, like a logic bug or failed bounds check.

I can see some arguments that might persuade the NSA to run an attack like this

  - gathers real world data on detection of supply attacks
  - serves as a wake-up call for a software community that has grown complacent on the security impact of dependencies
  - in the worst case, if no one finds it then hey, free backdoor