Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Well, there were two different backdoors:

- This one could be the work of an intern, maybe a smart one but definitively it doesn't seems very sophisticated (we should look at the code).

- The second one, we are not sure it actually existed but just that someone changed the parameters for the PRNG. But if it existed, well, it was a very sophisticated attack.

But that's not the point of your question! A string compare with an if is pretty easy to hide in the code. Especially if the string looks like a logging string. I'm pretty sure in a big patch could pass through a quick code review. Calling an HMAC function or hiding it in the auth code that already call the HMAC function is much more complex. Plus it is much more difficult to generate a password, salt couple where both the salt and the HMAC seems legit code. Even for an intelligence agency or an attacker with huge resources, it is difficult to get such result!



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: