Well.. that's exactly what happened to Solarwinds last year, didn't it?
Actually smarter than that - they got into the build system and added the malicious code in the build process so you couldn't see it in the repository.
Do you think it's that difficult for a state sponsored body to infiltrate into a commercial company?
Comments
Well.. that's exactly what happened to Solarwinds last year, didn't it?
Actually smarter than that - they got into the build system and added the malicious code in the build process so you couldn't see it in the repository.
Do you think it's that difficult for a state sponsored body to infiltrate into a commercial company?
The effort my big software company does on regards of requirements of releasing software, I would say yes.
Big companies like Nvidia have background checks, independent security teams etc.
Impossible? No. But easier and cheaper is still other means.