Possibly linux@lemmy.zip to Linux@lemmy.mlEnglish · 8 months agoXZ backdoor in a nutshelllemmy.zipimagemessage-square162fedilinkarrow-up11.23Karrow-down110 cross-posted to: linux
arrow-up11.22Karrow-down1imageXZ backdoor in a nutshelllemmy.zipPossibly linux@lemmy.zip to Linux@lemmy.mlEnglish · 8 months agomessage-square162fedilink cross-posted to: linux
minus-squarewhereisk@lemmy.worldlinkfedilinkarrow-up13·8 months agoIdeally you need a double-blind checking mechanism definitionally impervious to social engineering. That may be possible in larger projects but I doubt you can do much in where you have very few maintainers. I bet the lesson here for future attackers is: do not affect start-up time.
minus-squareunderisk@lemmy.mllinkfedilinkarrow-up9·8 months agoI imagine if this attacker wasn’t in a rush to get the backdoor into the upcoming Debian and Fedora stable releases he would have been able to notice and correct the increased CPU usage tell and remain undetected.
Ideally you need a double-blind checking mechanism definitionally impervious to social engineering.
That may be possible in larger projects but I doubt you can do much in where you have very few maintainers.
I bet the lesson here for future attackers is: do not affect start-up time.
I imagine if this attacker wasn’t in a rush to get the backdoor into the upcoming Debian and Fedora stable releases he would have been able to notice and correct the increased CPU usage tell and remain undetected.