27 ms·
https://en.m.wikipedia.org/wiki/XZ_Utils_backdoor https://en.m.wikipedia.org/wiki/XZ_Utils_backdoor
by rty32 2y ago
https://en.m.wikipedia.org/wiki/XZ_Utils_backdoor https://en.m.wikipedia.org/wiki/XZ_Utils_backdoor
- marky1991 2y agoBut that involved one of the developers of said package committing malicious code and it being accepted and then deployed. How would this prevent that from happening? I thought this was about ensuring the code that developers pushed is what you end up downloading.
- rty32 2y agoNo, part of the malicious code is in test data file, and the modified m4 file is not in the git repo. The package signed and published by Jia Tan is not reproducible from the source and intentionally done that way. You might want to revisit the script of xz backdoor.
- epcoa 2y agoAn absolutely irrelevant detail here. While there was an additional flourish of obfuscation of questionable prudence, the attack was not at all dependent on that. It’s a library that justifies all kinds of seemingly innocuous test data. There were plenty of creative ways to smuggle in selective backdoors to the build without resorting to a compromised tar file. The main backdoor mechanism resided in test data in the git repo, the entire compromise could have.