First off, great article.<p>But, like so many other articles about security vulnerabilities, there seems to be a general attitude among most people (including many IT shops) that "it's an isolated incident", and "the experts will fix it...".<p>"It's an isolated incident", and "The experts will fix it...".<p>They said the same thing about Spectre, Meltdown, Rowhammer attacks, what have you.<p>"It's an isolated incident", and "The experts will fix it...".<p>Well, if you read HN long enough, you'd know that there's too much of this on too regular a basis to continue to espouse those views.<p>I'm going to go for broke here.<p>I'm going to put on my conspiracy "what if" tin-foil hat, and ask two questions.<p>The first is related to Virus-Checking and Security Software -- like Norton, McAfee, etc. how do we know that any of it doesn't contain remote code execution (aka major security) vulnerabilities?<p>You see, if I were the bad guys, <i>that's where I'd put it</i>.<p>Also, let's say you have Nation States. Could you see one of these guys "persuading, for the good of their country" one or more of their same-nationality corporations to put such vulnerabilities into their "Security" software?<p>In other words, maybe you have a Chinese producer of anti-virus/security software, and maybe it has little "surprises" for non-Chinese Citizens.<p>Maybe you have an American producer of anti-virus/security software, and it too has little "surprises" for non-American Citizens.<p>You see? Nation A thinks that it's permissible and OK for it to compromise Nation B's "Security" software. And Nation B thinks the same thing, but in reverse.<p>Even if Nation States are removed from the equation, you still have the Virus Checker/Security software company themselves. How do you know that random employees at that company haven't tainted that software in some way?<p>In other words, "Who guards the guardians?"<p>Which is my second question.<p>It's an ancient philosophical question.<p>"Who guards the guardians?"<p>We The People - do not seem to be doing such a good job these days...<p>All I know is that you might be seeing a whole lot more "isolated incidents" that "the experts will have to fix" in the future, unless We The People - step up to the plate...