▲ 1472 ▼ Proprietary vs Open Source Backdoors (lemy.lol) submitted 1 year ago by icegladiator@lemy.lol to c/linuxmemes@lemmy.world 96 comments fedilink hide all child comments
[–] MrMobius@sh.itjust.works 12 points 1 year ago (2 children) Makes me remember, wasn't there a well respected dev who, out of the blue, decided to add a vulnerability in a linux package last year? permalink fedilink source hideshow 4 child comments replies: [–] mic_check_one_two@lemmy.dbzer0.com 30 points 1 year ago* That’s what this meme is referencing. That was the XZ Utils backdoor. The contributor spent 5 years gaining the lead dev’s trust, waited for the lead dev to get busy with other things, then basically bullied the lead dev into handing over control of the project. They quietly pushed an SSH backdoor. And then they were almost immediately called out by a dude who was running benchmarks and realized that his SSH requests were taking like 5ms longer than they should. That delay was because the backdoor was checking the SSH request against a table of backdoor requests, to see if it should allow the connection even if the UN/PW was wrong. The big concern was that the SSH system was used all over the world. But rolling back to a previous version was easy, and most systems hadn’t updated yet anyways. permalink fedilink source parent [–] Jumuta@sh.itjust.works 23 points 1 year ago (2 children) yeah this meme is referencing xz permalink fedilink source parent hideshow 4 child comments replies: [–] orosus@lemmy.world 6 points 1 year ago Para hablantes de español, este video explica la vulnerabilidad de XZutils, a la que hace referencia este meme: https://youtu.be/mTpDmhF4BSw permalink fedilink source parent [–] SanityRequired@lemmy.world 4 points 1 year ago https://m.youtube.com/watch?v=F7iLfuci75Y Greate little video on it permalink fedilink source parent
[–] mic_check_one_two@lemmy.dbzer0.com 30 points 1 year ago* That’s what this meme is referencing. That was the XZ Utils backdoor. The contributor spent 5 years gaining the lead dev’s trust, waited for the lead dev to get busy with other things, then basically bullied the lead dev into handing over control of the project. They quietly pushed an SSH backdoor. And then they were almost immediately called out by a dude who was running benchmarks and realized that his SSH requests were taking like 5ms longer than they should. That delay was because the backdoor was checking the SSH request against a table of backdoor requests, to see if it should allow the connection even if the UN/PW was wrong. The big concern was that the SSH system was used all over the world. But rolling back to a previous version was easy, and most systems hadn’t updated yet anyways. permalink fedilink source parent
[–] Jumuta@sh.itjust.works 23 points 1 year ago (2 children) yeah this meme is referencing xz permalink fedilink source parent hideshow 4 child comments replies: [–] orosus@lemmy.world 6 points 1 year ago Para hablantes de español, este video explica la vulnerabilidad de XZutils, a la que hace referencia este meme: https://youtu.be/mTpDmhF4BSw permalink fedilink source parent [–] SanityRequired@lemmy.world 4 points 1 year ago https://m.youtube.com/watch?v=F7iLfuci75Y Greate little video on it permalink fedilink source parent
[–] orosus@lemmy.world 6 points 1 year ago Para hablantes de español, este video explica la vulnerabilidad de XZutils, a la que hace referencia este meme: https://youtu.be/mTpDmhF4BSw permalink fedilink source parent
[–] SanityRequired@lemmy.world 4 points 1 year ago https://m.youtube.com/watch?v=F7iLfuci75Y Greate little video on it permalink fedilink source parent