"open source needs more funding!"
*nation state pays for backdoor*
"not like that!"
"open source needs more funding!"
*nation state pays for backdoor*
"not like that!"
To be fair, this has similar vibes:
"I need money for rent!"
"Mobster pays you to stab someone."
"Not like that!"
@eugenialoli @tenderlove From what I've heard so far it's still not clear more than one person was involved (even if more than one account was), but that certainly is possible.
Some nation states would definitely do something like this, but part of the lesson here is that it didn't take a lot of resources. It could also be someone who got laid off a couple years from an industry job and found a scheme to make some money and get back at the industry. And do the kind of programming they enjoy.
@tenderlove :D
BTW nation state can out a gun on the maintainer andnforce them to release a vulnerable package.
Or put them in a prison without anyone noticing and take the ownership of the package.