Reply to post: How do you get bad things into someone else's software?

More patches for SolarWinds Orion after researchers find flaw allowing low-priv users to execute code, among others

Anonymous Coward
Anonymous Coward

How do you get bad things into someone else's software?

Outline of a purely fictitious story.....something Lee Childs might write in the next little while....purely fictitious!

The main protagonists are bad actors working in Ruritania. Here's the plot outline. Actions #1 through #6 are Ruritanian:

1. Read up on "agile", "scrum", "devops". Lots of boosters out there!

2. Read up on software companies who are using "agile", "scrum" or "devops".

3. Do some probing on the systems used by said software companies. If you find that the development environment is "accessible", move to step #4.

4. Insert bad stuff into the "agile", "scrum" and "devops" process stream.......no one will notice!

5. Wait six months for the bad stuff to hit the streets.

6. Bingo!!

7. Jack Reacher gets the job of cleaning up Ruritania!

POST COMMENT House rules

Not a member of The Register? Create a new account here.

  • Enter your comment

  • Add an icon

Anonymous cowards cannot choose their icon