Hacker News new | ask | show | jobs
by MikusR 804 days ago
The xz thing was just 10 days ago.
1 comments

Google is everyday.

Dude acts as if when it’s open source he conducts a code audit before installing anything.

xz just proves how dumb this mindset actually is.

I'd say the opposite, xz proved how much effort it is to actually backdoor widely used open-source software as opposed to something where the Russian government (or another one) can just go knocking.

Nothing is perfect of course but the attack was insane in terms of complexity.

Im sure state level actors are building clones of old software with little network functionality to pwned people en mass.