Sabitlenmiş Tweet
Ryouchi
219K posts

Ryouchi
@ryouchi
趣味:空想 特技:妄想 難しいことを考えるのは苦手です。 キーワード:ソフトバンクホークス #sbhawks / お腹すいた / ミステリー小説 / 情弱
japan Katılım Nisan 2007
990 Takip Edilen667 Takipçiler
Ryouchi retweetledi

When Andres Freund, Linux kernel contributor & Microsoft engineer was debugging slow SSH logins on his Debian machine in March 2024, he noticed something weird:
liblzma (part of XZ Utils) was using way too much CPU power, so he kept digging, and what he uncovered was a multi-year supply-chain attack!
An attacker using the name “Jia Tan” had spent two years slowly infiltrating the tiny XZ Utils project, a compression library used by virtually every major Linux distribution.
The backdoor wasn’t in the source code. It was hidden deep inside the build scripts. It would have given the attacker remote root access on millions of servers the moment a specially crafted SSH key was used.
Freund caught it days before it would have shipped in Debian, Fedora, Ubuntu and more.
One man, one anomaly, one routine debug session saved the internet from a potential catastrophe.
Respect!

English



