Conversation

This Tweet was deleted by the Tweet author. Learn more
Replying to and
It would be difficult for an unknown individual or unknown/untrusted organisation. It's less difficult for a respected university willing to sacrifice its reputation.
3
15
Replying to and
OK so I did understand correctly. So to reiterate, I believe that anyone could submit a patch to the Linux kernel introducing an intentional vulnerability, and I believe that the research as well as Greg's response support this.
2
Replying to and
I don't believe that there was a strong implicit trust attached to the edu email, and Greg as much states that patches don't review that kind of scrutiny. It's no one's fault really, it's not practical to expect them to catch bugdoors.
1
People regularly sell access to those emails due to exclusive products, etc. for US university students. You can go to eBay right now and pay for access. It costs a few dollars. Not relevant to this but that would be a pretty weak argument if it was how they were submitted.
1