Comment by goodpoint

4 years ago

The reward for implanting a rogue employee is orders of magnitude higher, with the ability to plant backdoors or weaken security for decades.

And that's why nation-state attackers do it routinely.

Yes, it’s a different problem that’s way less likely to happen and potentially more impactful, hence not comparable. And entities with enough resources can do the same to open source, except with more risk; how much more is very hard to say.

  • Despite everything, even NSA is an avid user of Linux for their critical systems. That says a lot.