logoalt Hacker News

embedding-shapeyesterday at 4:31 PM1 replyview on HN

> The point is they added another attack surface, however small, and another code path that should be tested.

I dunno, "attack surface" to me means "facilitate opening/vulnerability somehow" and none of the easter egg code I've seen has done that. You have any concrete examples where a easter egg made possible a security vulnerability that wouldn't be possible otherwise?

But yes, another code path created by easter eggs that wasn't tested I've seen countless of times, but never been an issue, but maybe our easter eggs always been too small in scope for that.


Replies

jedbergyesterday at 4:35 PM

The most famous is the Xbox hack that was only possible because of an Easter Egg:

https://security.stackexchange.com/questions/144202/are-ther...