Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

...or forces a well-respected contributor to add evil code under duress.



Imagine a state actor offering retirement money and a plane ride to a non-extradition island nation for a few commits. Assuming the contributor is using a VPN already, no one would know they were adding surreptitious backdoors in their code.

The only solution is to scope security relevant functions and add a multi stage formal verification process before freezing the commits. This assumes no collusion.




Consider applying for YC's Fall 2025 batch! Applications are open till Aug 4

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: