I still find it ironic that the dude that found the malicious code was a Microsoft employee.
post
replies:
I feel like the latter really happened. That sounds too specific to be made up.
replies:
permalink
fedilink
source
parent
hideshow 3 child comments
You would be correct:
replies:
permalink
fedilink
source
parent
hideshow 2 child comments
This story does make me worried though, that this is the case where they were caught, and there are many more where they weren’t caught.
replies:
permalink
fedilink
source
parent
permalink
fedilink
source
parent
I'm more worried about the top case, honestly. That probably happens way more often and found out less often because the stuff isn't opensource.
We had this discussion in another thread. This was a most likely state sponsored action with huge time investment. It was also highly complicated because it is nearly impossible to hide this stuff due to the number of eyes on the code. Of course it is possible, but its not feasible to assume its somehow massive.
all 9 comments