|
|
|
|
|
by dralley
110 days ago
|
|
Red Hat noticed that something was off, but there was a new version published by "Jia Tan" that fixed the warnings and the performance issue, so it's not really clear that the original version would have still gotten as deep of an investigation as would have been needed to find the issue. It's possible though. The noise around it did at least put Freund on alert and we should be very glad both that "Jia Tan" made the mistakes they made originally and that Freund followed up on their gut feeling |
|
One wonders whether the xz backdoor would have been discovered if slightly less obfuscation was used.
The whole xz incident is a pretty strong argument to:
a) change practice from including binary (opaque) test files themselves to human-readable scripts and tooling that build test files on-demand,
b) raise suspicion of any binaries included in open source projects, and
c) create much more scrutiny around dependencies of 'highly scrutinised' packages like OpenSSH.
It's a shame that there isn't a foundation (that I'm aware of) that can donate time and effort of vetted developers to foundational open source projects like xz.