Earlier quoted context omitted.
> it enabled it in the first place it took roughly two years including social engineering. I'd say the same approach is much easier in a big software company.
How do you mean?
In a big company it's much easier to slip it in. Code seemingly less relevant for security is often not reviewed by a lot of people. Also, often people don't really care and just sign it off without a closer look.
And when it's merged, no one will ever look at it again, other than with FOSS.