The XZ Utils backdoor, discovered last week, and the Heartbleed security vulnerability ten years ago, share the same ultimate root cause. Both of them, and in fact all critical infrastructure open source projects, should be fixed with the same solution: ensure baseline funding for proper open source maintenance.

1 point
*

Hear me out. What if instead we just included a respected developers open-source project into our multi billion dollar product, paid them nothing, and gave them the pressure of ensuring it’s working for millions of users at the threat of their reputation until their mental health is in shambles? 🤔

permalink
report
reply
7 points

I wouldn’t say quite the same root cause — the xz back door was clearly intentional, but I don’t recall the Heartbleed bug having been intentional, and developer responsible has denied allegations to that effect. There can be no doubt in the xz case of malicious intent.

permalink
report
reply
2 points

No, they do not have the same root cause. Heartbleed was an apparent typo from a known figure missed in a code review. xz was a sustained effort of external pressure to get an anonymous person access to add obfuscated code that would probably not be reviewed, and even if reviewed would probably pass.

permalink
report
reply
16 points

Fuck me, ten years already?

permalink
report
reply
5 points

Thinking the same thing. WTF

permalink
report
parent
reply

Technology

!technology@lemmy.ml

Create post

This is the official technology community of Lemmy.ml for all news related to creation and use of technology, and to facilitate civil, meaningful discussion around it.


Ask in DM before posting product reviews or ads. All such posts otherwise are subject to removal.


Rules:

1: All Lemmy rules apply

2: Do not post low effort posts

3: NEVER post naziped*gore stuff

4: Always post article URLs or their archived version URLs as sources, NOT screenshots. Help the blind users.

5: personal rants of Big Tech CEOs like Elon Musk are unwelcome (does not include posts about their companies affecting wide range of people)

6: no advertisement posts unless verified as legitimate and non-exploitative/non-consumerist

7: crypto related posts, unless essential, are disallowed

Community stats

  • 3.5K

    Monthly active users

  • 2.9K

    Posts

  • 45K

    Comments

Community moderators