9 ms·
Technologist vs. spy: the xz backdoor debate
- egberts1 3y agoAll that can be avoided by doing really good sets of unit tests and integration tests, then incorporate its test result into the validation part of the repository.
- deleted 3y ago[deleted]
- bediger4000 3y agoThis is an interesting article. Zalewski is almost unique in the ability and credibility to write this. He used to work for Google in infosec, he's got a lot of experience writing code, and he no longer works for a big corporation, so he's free to say what he thinks.
- trogdor 3y ago>In other words, all signs point to this being a professional, for-pay operation — and it wouldn’t be surprising if it was paid for by a foreign government. Or a not-foreign government…
- rurban 3y agoWe just call them state actors
- shnkr 3y ago>The relationship with commercial vendors isn’t always healthy, but many major OSS projects are supported to a significant extent. Almost always the so called "community" supporting a OSS project is an employee of a commercial vendor who is only interested as long as he is assigned to the project or task. The solution is to have a full time owners and maintainers for all the critical projects and the government has to foot the bill. The govt can setup a division to identify such projects.
- gizmo686 3y agoI'm amazed we have gotten this far without something like that happening. Critical infastructure is built ontop of this pile of software that is all being maintained by. If every major piece of infastructure (power plant, water treatment plant, etc) would dedicate 1 full time engineer to 1 open source dependency that they use, there would be more than enough man power to solve it.
- forgotmyinfo 3y agoWe can't even support actual critical physical infrastructure anymore, like roads, bridges, and the power grid. And that stuff has very obvious immediate consequences when it breaks. Try explaining to your local octogenarian senator what xz is and why OpenSSH shouldn't just be funded by whatever spare change we find in the couch cushions.
- GabeIsko 3y agoGovernments will just outsource it to commercial contractors at this point.
- diogocp 3y agoGovernment: launches a years-long covert operation to take over maintainership of critical project in order to insert a backdoor. HN comments: the solution is for government to maintain these critical projects.
- kaliqt 3y ago
- colejohnson66 3y agoMore evidence that the OSS community needs to drop the “many eyes” theory of security
- daghamm 3y agoOn the contrary. This was detected before it reached major distributors. The only major one hit by this was homebrew, but they have never understood security anyway.
- FireBeyond 3y ago> The only major one hit by this was homebrew, but they have never understood security anyway. MacOS doesn't ship with sshd running out of the box, and vanishingly few people ever enable it.
- daymanstep 3y agoThat's not the issue here. The xz backdoor author could have used the same technique to hijack any application that linked to xz, not just sshd.
- soraminazuki 3y ago> The only major one hit by this was homebrew, but they have never understood security anyway. Do you have any evidence that other distros wouldn't have done the same? What measures do other distros have in place that would've stopped the inclusion of the backdoor had they not been alerted at the right time?
- mhh__ 3y agoAs opposed to? The buck has to stop at a human somewhere
- derbOac 3y agoI guess to me it suggested even more eyes would be even better.
- publius_0xf3 3y ago>In fact, here’s an interesting thought: perhaps they have known for a while. Would we be able to tell the difference between a carefully-timed disclosure — presumably engineered to conceal “methods and sources” — and a serendipitous discovery?