Skip to content

Commit

Permalink
chore: added links
Browse files Browse the repository at this point in the history
  • Loading branch information
himazawa committed Mar 31, 2024
1 parent c8738c5 commit e324ee1
Showing 1 changed file with 1 addition and 1 deletion.
2 changes: 1 addition & 1 deletion content/posts/xz-backdoor/index.en.md
Original file line number Diff line number Diff line change
Expand Up @@ -92,7 +92,7 @@ TL;DR: there isn't an actual solution
### Trust issues
![](https://imgs.xkcd.com/comics/dependency_2x.png)

`xz` is a software mainteined (up until 2022) by 1 single guy. Later another maintainer joined but unfortunately for us, it was the same guy pushing the backdoor to upstream.
`xz` is a software mainteined (up until 2023) by 1 single guy. Later another maintainer joined but unfortunately for us, it was the same guy pushing the backdoor to upstream.
This crashes against the fact that `xz` is an incredibly popular package available in a lot of distributions and being a dependency of many softwares.

This was likely seen by the attacker as a gold mine since it was easy to get the role of maintainer of the project and push the malicious code.
Expand Down

0 comments on commit e324ee1

Please sign in to comment.