← Back to context

Comment by ceroxylon

1 day ago

If you own a network and the servers, you can DPI every single packet and see literally every bit of information. All of the text to the "forum" that they created must have been in -outbound- packets to their compromised package manager, by definition. If they can't properly analyze network traffic, they should not be running 'sandboxes'.

Anything beyond baseline would be observable- silence, malformed packets, too much egress, unusually large packets, etc