Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

We were lucky that the backdoor called attention to itself, because it impacted the performance off ssh and introduced valgrind warnings.


Doesn't that further suggest non-state actor(s)?


I've heard that it was only detected because the developer that found it was using different compiler flags than the default. Under default settings, the backdoor was stealthier.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: