• What we need to take away from the XZ Backdoor (openSUSE News)

    From LWN.net@1337:1/100 to All on Fri Apr 12 14:00:06 2024
    What we need to take away from the XZ Backdoor (openSUSE News)

    Date:
    Fri, 12 Apr 2024 13:55:34 +0000

    Description:
    Dirk Mueller has posted a
    lengthy analysis of the XZ backdoor on the openSUSE News site, with a
    focus on openSUSE's response. Debian, as well as the other affected distributions like openSUSE
    are carrying a significant amount of downstream-only patches to
    essential open-source projects, like in this case OpenSSH. With
    hindsight, that should be another Heartbleed-level learning for the
    work of the distributions. These patches built the essential steps
    to embed the backdoor, and do not have the scrutiny that they
    likely would have received by the respective upstream
    maintainers. Whether you trust Linus Law or not, it was not even
    given a chance to chime in here. Upstream did not fail on the
    users, distributions failed on upstream and their users here.

    ======================================================================
    Link to news story:
    https://lwn.net/Articles/969591/


    --- Mystic BBS v1.12 A47 (Linux/64)
    * Origin: tqwNet UK HUB @ hub.uk.erb.pw (1337:1/100)