Something interesting about this is that proper code management practices would mean there would have to be a chain-of-command having knowledge of the need for a specific code commit that targets a single user with a surveillance backdoor. Could an approached employee say "I have to run this past software engineer X" before it will even be allowed to commit, so software engineer X is read-in, but he has to get auth f…
Also, what exactly happens if the code is worked on in teams and/or available for any people in the company (and it sure is), and if another developer questions the committed code or attempts to change or remove it? Does such code gets explicitly painted "don't remove, don't edit, don't ask any questions"? Suddenly we get code in our product that nobody cannot talk about, nobody should understand, and nobody can fix…
This would flag the code as 'interesting' to any other members of the development team, and it would likely make it obvious which account is being specifically targeted, which works against the secrecy required of the whole thing.