|
|
|
|
|
by shoddydoordesk
220 days ago
|
|
You are dismissing the seriousness of this. Their package manager is widely used. One would only need to compromise their build servers to wreak havoc. Didn't they have a vulnerability in their firmware download tool like a minute ago? The difference between OpenWRT and Linux distros is the amount of testing and visibility. OpenWRT is loaded on to residential devices and forgotten about, it doesn't have professional sysadmins babysitting it 24/7. Remember the xz backdoor was only discovered because some autist at Microsoft noticed a microsecond difference in performance testing. |
|
Is it "scary" to think about OpenWRT potentially getting hacked? If you get scared by theoretical possibilities in software, sure. Is it relevant? Not exactly. Are companies' official servers more secure than an open-source project's servers? In this case, apparently not.