▲ | gtsop 2 days ago | |||||||||||||||||||||||||
So rossmann literally feared of a patch that was like this getting into graphene if (user is rossmann) {
}makes me think who is paranoid here. | ||||||||||||||||||||||||||
▲ | fph 2 days ago | parent | next [-] | |||||||||||||||||||||||||
Note that this patch would have to be sent out to all users though, since I don't think there is an authentication mechanism that lets them send out different upgrades to different users. And if your whole business is a secure OS, it's a very risky proposition: you get caught doing this once, and your reputation is gone forever. | ||||||||||||||||||||||||||
▲ | bernoufakis 2 days ago | parent | prev [-] | |||||||||||||||||||||||||
Your example is a strawman, as a determined enough actor, especially a security expert(s) like GOS developers could pull it off and get such patch / exploit. The probability is not zero. It will probably not be obvious to spot, would be spread over multiple files of code that don't necessarily relate to each other at first glance, as many documented CVE illustrated (one that comes to mind given HN context is the XZ utils backdoor from last year for e.g.) Rossmann himself has no confidence to audit the code, so why take the risk ? Good enough reason to be "paranoid", or at least feel uneasy about it if you ask me. | ||||||||||||||||||||||||||
|