this post was submitted on 29 Mar 2024
0 points (NaN% liked)

Linux

53540 readers
1275 users here now

From Wikipedia, the free encyclopedia

Linux is a family of open source Unix-like operating systems based on the Linux kernel, an operating system kernel first released on September 17, 1991 by Linus Torvalds. Linux is typically packaged in a Linux distribution (or distro for short).

Distributions include the Linux kernel and supporting system software and libraries, many of which are provided by the GNU Project. Many Linux distributions use the word "Linux" in their name, but the Free Software Foundation uses the name GNU/Linux to emphasize the importance of GNU software, causing some controversy.

Rules

Related Communities

Community icon by Alpár-Etele Méder, licensed under CC BY 3.0

founded 5 years ago
MODERATORS
top 9 comments
sorted by: hot top controversial new old
[–] [email protected] 1 points 1 year ago

Some no-name came and without any problems asked to become a maintainer in a project used in almost any distro, took it over, put a backdoor in there and no one had any questions? In this case, everything turned out thanks to pure chance. Noname screwed up his backdoor, which attracted the attention of a guy from Microsoft, and out of boredom, he dug up what was what. And if I hadn’t messed up, or that guy from Microsoft decided to go drink beer instead of poking around in the xz code, then no one would have discovered anything. It’s scary to imagine how many of these nonames are sitting in all these thousands of open source projects, waiting in the wings to roll out a malicious patch.

[–] [email protected] 0 points 1 year ago* (last edited 1 year ago) (1 children)

They noticed that some ssh sessions took 0.5 seconds too long under certain circumstances. 😲

Holy hell that's good QA.

[–] [email protected] 0 points 1 year ago (1 children)
[–] [email protected] 0 points 1 year ago

Don't see why you're being downvoted, the person in question who discovered this is a postgres maintainer employed by Microsoft.

[–] [email protected] 0 points 1 year ago (1 children)

Damn, it is actually scary that they managed to pull this off. The backdoor came from the second-largest contributor to xz too, not some random drive-by.

[–] [email protected] 0 points 1 year ago (1 children)

It would be nice if we could press formal charges

[–] [email protected] 1 points 1 year ago

Assuming that it's just that person, that it's their actual name and that they're in the US...

[–] [email protected] 0 points 1 year ago (1 children)
[–] [email protected] 1 points 1 year ago

In the fallout, we learn a little bit about mental health in open source.

Reminded me of this, relevant as always, xkcd:

Image