The XZ Utils backdoor, discovered last week, and the Heartbleed security vulnerability ten years ago, share the same ultimate root cause. Both of them, and in fact all critical infrastructure open source projects, should be fixed with the same solution: ensure baseline funding for proper open source maintenance.

You are viewing a single thread.
View all comments
3 points

That’s a hell of a stretch of same root cause. Funding wouldn’t prevent bad actors from slipping in vulnerabilities into commits.

permalink
report
reply

Security

!security@lemmy.ml

Create post

Confidentiality Integrity Availability

Community stats

  • 38

    Monthly active users

  • 217

    Posts

  • 352

    Comments

Community moderators