• shotgun_crab@lemmy.world
    link
    fedilink
    arrow-up
    49
    ·
    edit-2
    6 months ago

    Still paniking, cause the backdoor was apparently targetting Debian servers, it was discovered just by chance and the “mantainer” made commits for 2 years in the same repo

      • dan@upvote.au
        link
        fedilink
        arrow-up
        28
        ·
        6 months ago

        and it was only discovered accidentally, when someone was profiling some stuff, noticed SSH using a bit too much CPU power when receiving connections even for invalid usernames/passwords, and spent the time to investigate it more deeply. A lot of developers aren’t that attentive, and it could have easily snuck through.

          • dan@upvote.au
            link
            fedilink
            arrow-up
            5
            ·
            6 months ago

            I’ve been meaning to start blogging again. It’s just been a lack of free time. Need to think of ideas, too.

            • Possibly linux@lemmy.zip
              link
              fedilink
              English
              arrow-up
              1
              arrow-down
              1
              ·
              6 months ago

              I’ve never read your blogs but I think it would be good for more people to do write ups on the XZ backdoor. There is a lot that can be learned and improved