• SatyrSack@lemmy.sdf.org
    link
    fedilink
    arrow-up
    1
    ·
    7 months ago

    Immediately get noticed

    Realistically, though, we are only aware of that one because it was noticed in that unlikely scenario and then widely reported. For all we know, most open source backdoors are alive and well in our computers, having gone unnoticed for years.

    • towerful@programming.dev
      link
      fedilink
      arrow-up
      1
      ·
      7 months ago

      Yup.
      But in open source it CAN be noticed, by anyone determined enough to dig into its side effects.
      Proprietary software? You file a regression bug that startup takes 500ms longer, and it might get looked at.

      Also, backdoors that are discovered in open source software improve automated software auditing.