4 ms·
The backdoor was possible because Debian introduced a dependency into sshd, libsystemd, which in turn linked to liblzma. Official sshd does not have a systemd d
by armitron 3y ago
The backdoor was possible because Debian introduced a dependency into sshd, libsystemd, which in turn linked to liblzma. Official sshd does not have a systemd dependency in the same way that official sshd back in 2008 did not suffer from a predictable PRNG.
Debian is also 100% at fault here and I hope this slap in the face makes them reconsider their poor security practices. Amateur package maintainers should not be overstepping their job (packaging) and enabling disastrous vulnerabilities in security-critical software.
- cpach 3y agoYou have a point there. For the record, Fedora was affected too.
- cesarb 3y agoThat's ridiculous. Adding the dependency to libsystemd in no way created any vulnerability. Even the indirect dependency on liblzma didn't add any vulnerability. It took a separate malicious maintainer doing a later change to liblzma so that it ran code when the library was loaded to create the vulnerability.
- armitron 3y agoI wrote 'was possible' and 'enabled', not 'created'. By paying more attention to what others write you'll avoid superficial dismissals that prevent you from improving your understanding of complex issues. The creation of this backdoor did not take place in a vacuum. Can you imagine the same person trying to introduce build changes and binary test cases into openssh? This backdoor was crafted in this particular way _specifically_ to exploit the fact that sshd in distributions such as Debian is being indirectly linked with lzma.
- throwaway7356 3y ago> Amateur package maintainers should no [...] At least there is no lack of amateur enthusiasts telling people how they are wrong. :)