You're viewing a single thread.
View all comments
162
comments
The scary thing about this is thinking about potential undetected backdoors similar to this existing in the wild. Hopefully the lessons learned from the xz backdoor will help us to prevent similar backdoors in the future.
31 0 ReplyI think we need focus on zero trust when it comes to upstream software
19 1 Replyexactly, stop depending on esoteric libraries
2 0 ReplyIt is fine to use them just know how they work and check the commit log.
That of course requires you to pull from got instead of a tarball
1 0 Replythis was well hidden. not sure anyone would have spotted this by checking commit log
1 0 ReplyIt was hidden in the Tarball
1 0 Replyi'm not an expert, but my reading was that it was hidden in a binary used for testing EDIT: oh yeah, i see what you mean
1 0 Reply
You've viewed 162 comments.
Scroll to top