Hacker News new | ask | show | jobs
by Delk 246 days ago
The question of whether the xz format is a good choice for long-term archival is entirely unrelated to backdoors or open source supply chain security.
1 comments

No they're the same. Why do you think xz was targeted? It's a giant slippery hairball.
> Why do you think xz was targeted?

Possibly for any number of reasons. A sole maintainer with a bit too little capacity to keep up the development. A central role as a dependency for crucial packages in a couple of key distros.

What would be the connection between the backdoor (or indeed any supply chain security) and any design details of the xz file format? How would the backdoor have been avoided if the archive format were different?