Hacker News new | past | comments | ask | show | jobs | submit login

You don't need a "ec2" user. A backdoor can just allow root login even when that is disabled for people not using the backdoor.

It just requires the SSH port to be reachable unless there is also a callout function (which is risky as people might see the traffic). And with Debian and Fedora covered and the change eventually making its way into Ubuntu and RHEL pretty much everything would have this backdoor.




Join us for AI Startup School this June 16-17 in San Francisco!

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: