4 ms·
the list of contributors is huge, you just need to hack one person https://contributors.debian.org/ https://contributors.debian.org/ not to mention libraries l
by throwaway71271 3y ago
the list of contributors is huge, you just need to hack one person https://contributors.debian.org/ https://contributors.debian.org/
not to mention libraries like libxslt that is used by like half the packages
even kernel.org was hacked, and git saved us, and luckily it was before the sha1 collision attacks were viable
https://www.reddit.com/r/linux/comments/k0mco/kernelorg_compromised/ https://www.reddit.com/r/linux/comments/k0mco/kernelorg_comp...
https://crypto.stackexchange.com/questions/99767/how-easy-is-it-in-2022-to-find-a-sha1-collision https://crypto.stackexchange.com/questions/99767/how-easy-is...
- hobobaggins 3y ago> you just need to hack one person bribes are probably quicker and easier.