>start contributing code fixes to multiple open-source projects>raise issues on GitHub for problems >work yourself up the food chain>use sock puppets to complain about the author of a major project>become an appointed maintainer of that project>start inserting malicious codeAnd all it took was a single autist being triggered by ssh sessions starting a fraction of a second slower than normal to be caught. Over 2 years of work down the drain. But this raises a question: is this happening right now on other projects with other people?
Has anyone ever figured out who this was and who he was affiliated with by the way?>The IRC channel #tukaani on Libera Chat has been a little more active recently. :-)>https://www.mail-archive.com/xz-devel@tukaani.org/msg00634.html
half-second.com has some sort of book on this, haven't read it yet but there you go
>>109401296You should always assume that is the case. That said one trick to mimize the risk is to reduce standardization: the less widespread the surface of the attack the less convenient the investment in preparing such attack vectors, example in case the xz bug only affected systems where liblzma linked to openssh, if you were to use a less centralized solution (or even better not using systemd cancer to begin with) you would be also unaffected.One of the original strengths of linux security was its "fragmented" nature other than being subject of constant scrutiny.
>>109401296>is this happening right now on other projects with other people?yes. There are tons of people trying similar on other projects. It's pretty fucking obvious and was already said enough times before that
>>109401296it was random nobody that uploaded the malicious compiled binaryit wasn't malicious code iirc
>>109401296Thanks to MicroSlop, xz is not stealing our dick pics.Based MicroJeet
>>109401478>Release early, Release oftenSo big tech are the good guys?