|
|
|
|
|
by chgs
670 days ago
|
|
This wasn’t a contributor to OpenSSH, it was a deep level supply chain attack - something that closed source commercial companies are not immune to. Given how much closed source companies love BSD/apache/etc licenses where they can simply use these low level libraries and charge for stuff on the top I’m not sure how they would be immune from such an attack. The risk from this was highlighted in xkcd back in 2020 https://xkcd.com/2347/ |
|