タグ

ブックマーク / research.swtch.com (1)

  • research!rsc: Timeline of the xz open source attack

    Posted on Monday, April 1, 2024. Updated Wednesday, April 3, 2024. Over a period of over two years, an attacker using the name “Jia Tan” worked as a diligent, effective contributor to the xz compression library, eventually being granted commit access and maintainership. Using that access, they installed a very subtle, carefully hidden backdoor into liblzma, a part of xz that also happens to be a d

    NOV1975
    NOV1975 2024/04/04
    これは面白い…が、特定のボランティア的個人に依存しているOSSプロジェクトはそのこと自体が脆弱性を持つとみなさなければならないところまであと一歩な感じだよなあ。
  • 1