• dan@upvote.au
    link
    fedilink
    arrow-up
    28
    ·
    7 months ago

    and it was only discovered accidentally, when someone was profiling some stuff, noticed SSH using a bit too much CPU power when receiving connections even for invalid usernames/passwords, and spent the time to investigate it more deeply. A lot of developers aren’t that attentive, and it could have easily snuck through.

      • dan@upvote.au
        link
        fedilink
        arrow-up
        5
        ·
        7 months ago

        I’ve been meaning to start blogging again. It’s just been a lack of free time. Need to think of ideas, too.

        • Possibly linux@lemmy.zip
          link
          fedilink
          English
          arrow-up
          1
          arrow-down
          1
          ·
          7 months ago

          I’ve never read your blogs but I think it would be good for more people to do write ups on the XZ backdoor. There is a lot that can be learned and improved