Posted Dec 15, 2010 17:39 UTC (Wed) by danieldk (subscriber, #27876)
[Link]
At the very least, it has some plausibility.
Remember that Debian's OpenSSL was broken for two years without anyone noticing. If some package maintainer intentionally introduced such a bug, would anyone notice?
Proprietary software is even worse, since no third party can check the source. But it is still a viable attack route in free software.