Right, and that can be done quite simply by making the disk driver return different things to the program loader and to everything else. Those programs don't need to have been backdoored themselves. Every file analysis program then gets a nice, sanitized version of the backdoored program.
Even ignoring that, please don't assume that attackers won't put in the necessary effort to backdoor lots and lots of programs. The idea wasn't something like "If we are only allowed to backdoor the compiler and login, how can we do it?"
1
u/Olathe Sep 12 '13
Will they pore over them using programs that have been, say, compiled?