Remix.run Logo
lolc a day ago

You're saying that a state can upstream patches with planted backdoors. Thruth is, this is possible in all software. It's not specific to state-sponsored open source software. So your scenario is a reality whether you want it or not. And open source is not particularily vulnerable either. People forget this.

Now a lot of people would be angry if my state decided to spend money on security flaws. I imagine an elected representative try to explain how they wanted to misspend funds allocated to improve software and plant flaws instead. That would not go down well here or in Germany. Try to hire people for this in Germany and see how long you last till your little op is public.