[Video] How a malicious backdoor in XZ Utils threatened the Internet ecosystem

https://youtu.be/aoag03mSuXQ

TL;DW:
A video by Veritasium about how a single dependency (.xz) was momentarily compromised leading to the compromise of OpenSSH (which uses .xz as a dependency), which ultimately would have spelled out a master key access to Linux systems across the world.

Really cool how they explain and visualize LZ, Deflate, LZMA and RSA.

Shout-out to all the Open Source contributors out there! And a reminder to others to show your appreciation to those who dedicate time and resources to projects that often go unappreciated or for granted.

15 points · 2 comments · view on lemmy.world

2 Comments

itflows@feddit.org · 4 pts · 207d

Poor Tux. Abused as a symbol for anything that is somehow related to Linux or even open source.

teft@piefed.social · 3 pts · 207d

I love that no one would have caught the backdoor except some rando M$ employee noticed a half second delay in his connection during testing.

Makes you wonder how many backdoors (obfuscated and well hidden) have remained intact over the years.

ZippyBot@lemmy.zip · 0 pts · 207d
[ removed ]