5
exerceo
223d

This is why my trust in updates is low.

https://en.wikipedia.org/wiki/...

Updates aren't always good. Sometimes, they might introduce problems and anti-features.

(Also, didn't whoever introduced this backdoor on a wildly popular component of Linux expect to be caught?!)

Comments
  • 2
    Fucking hell.

    This shit is only going to get worse as the shit actors are losing their grip.
  • 2
    I can see it not getting caught if not for it causing performance issues to someone. Makes one wonder how many of these have gone unnoticed already.

    One takeaway is that you shouldn't accept a binary file to your repo unless you can verify what it is.
  • 1
    it would've probably been caught, just maybe not as quickly. They were rushing Fedora to include the patch so they knew they had limited time.
  • 1
    arguably it was also only found because of a substantial mistake; in public-facing servers, failed auth is actually a hot path within sshd so performance regressions have a huge impact.
  • 2
    With this hindsight, the next such attack will be optimized to hell to ensure that no one has a reason to poke around.
  • 6
    This smells like state sponsored work to me.
Add Comment