3 ms·
There are countless people who can do that and don't. There are almost certainly many people actively doing it still today. Thinking that the xz attack was extr
by swatcoder 2y ago
There are countless people who can do that and don't. There are almost certainly many people actively doing it still today. Thinking that the xz attack was extraordinary or difficult is a very big mistake.
It's news cycle should have conveyed a sense of "oh shit, we really do need to be watching for discretely malicious contributors" not "whoa, I can't believe there was someone capable of that!" -- it seems like you learned the wrong lesson.
- telgareith 2y agoI came to the realization over a year ago, that the only thing needed to be an "Advanced persistent threat" is an attention span. Not even a long one. Judging how many drive by's a random ipv4 address gets on aws, gcp, azure, or vultr- they get ignored if they get it wrong, and nobody notices until too late if they get it right.
- lesuorac 2y agoWell, the other take-away is that if somebody can put in the work to do that to hopefully get included into a linux distro; what are they doing to get included into MacOS / Windows?
- Cyphase 2y agoThey were targeting OpenSSH servers, not desktops.
- lesuorac 2y agoI mean people often use desktops to connect to servers. It's akin to putting an exploit into say some security software. It's probably going to have access to something you care about.
- guappa 2y agoWell linux distributions can be installed on windows so…