Hacker News new | ask | show | jobs
by xmodem 376 days ago
That was an attack targeting an optional dependency that receives significantly less scrutiny than OpenSSH proper. Which to be fair, is probably also the most plausible path if you wanted to attack Signal.

I would quibble with calling it "trivial" though.