Or found out in corporate code review / pentest. We just don’t know.
I get that we want to say FOSS is great due to the “many eyes/shallow bugs” thing, but that didn’t work for OpenSSL or log4j. The fact that it did now is great, but let’s not get carried away. It was just pure luck.
If anything it highlights how great open source actually is when it comes to security. People saw it and immediately flagged it.
I don’t think this one counts as a big win to be honest It was just freakish luck
It’s definitely freakish luck but at least it got found out. A closed source software would have gone through unnoticed.
the fact that it was found by luck, not methodically, to me implies that there probably are other backdoors we didn’t get lucky with.
Or found out in corporate code review / pentest. We just don’t know. I get that we want to say FOSS is great due to the “many eyes/shallow bugs” thing, but that didn’t work for OpenSSL or log4j. The fact that it did now is great, but let’s not get carried away. It was just pure luck.
Dude, the issue was found purely by coincidence, it very nearly made it through
Yes, but it didn’t. Has it made it through on closed software? Who knows?
Also this was a multi year effort that employed very complex knowledge. And still didn’t get thru.
If it’s multi year and very complex it’s telling that this is what it takes. The bar is very high.