XZ Hack - "If this timeline is correct, it’s not the modus operandi of a hobbyist. [...] It wouldn’t be surprising if it was paid for by a state actor."
XZ Hack - "If this timeline is correct, it’s not the modus operandi of a hobbyist. [...] It wouldn’t be surprising if it was paid for by a state actor."
![](https://lemmy.ml/pictrs/image/15c12519-4c63-4eb4-afb1-286687570b4d.jpeg?format=webp&thumbnail=128)
Well — we just witnessed one of the most daring infosec capers of my career. Here’s what we know so far: some time ago, an unknown party evidently noticed that liblzma (aka xz) — a relatively obscure open-source compression library — was a dependency of
![Technologist vs spy: the xz backdoor debate](https://lemmy.ml/pictrs/image/15c12519-4c63-4eb4-afb1-286687570b4d.jpeg?format=webp)
Thought this was a good read exploring some how the "how and why" including several apparent sock puppet accounts that convinced the original dev (Lasse Collin) to hand over the baton.