Conversation

The unsung heroes of today are all the backdoor authors who do proper benchmarking and profiling, so that they don't get caught because SSH logins are too slow.

4
8
1
@lcamtuf why is my system so slow?

oh wait are the backdoors having backdoors again?
0
0
1

@swelljoe@mas.to @lcamtuf@infosec.exchange More like they're actually already getting away with it in places we don't even bother to look.

1
1
0

@AlgorithmWolf @lcamtuf yes, I'm 100% sure there are back doors in dozens or hundreds of proprietary products that no one has found (and, I bet some of the ones that have been found have quietly been patched without disclosure), and a few in OSS projects that made it through. This one could have gone unnoticed for quite a while were it not for a lot of luck. Lots of people missed it. It's a real threat.

0
1
0