Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

> However, if this had been a mole in a company, he wouldn't be able to hide behind a > possibly anonymous fake persona and (likely) be immune from any consequences/fallout from > this attack. It would be harder to gain entry in the first place, he would have needed a > real identity.

Lots of companies hire remote workers sight unseen, and not all require proof of identity, and where they do, that proof can possibly be easily faked by someone willing to break the law.

Larger Open Source projects - e.g. Debian Developers, also have real-identity verification through chain of trust.

> Background checks may not be a big hurdle, but they're at least something more than > signing up for a GitHub account.

GitHub doesn't allow more than one free account per person. Companies might not look for employees sharing an IP address as much as GitHub does.

> He also wouldn't have had his posse of anonymous sock > puppet accounts to add pressure to the original maintainer.

Depending on the software, it might not be that hard to be a customer (or even pretend to be an employee of a known customer, if they aren't validating incoming requests claiming to be from customers enough) and add pressure for features that will provide cover for a backdoor, or even for a product that isn't a commercial success to be handed over to an external developer.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: