Top-level
3 comments
@danderson @raito @astrid the way we see it, the primary exploit here was the social one (see details at [1]). this is absolutely what passes for stealth on that front. [1] https://boehs.org/node/everything-i-know-about-the-xz-backdoor |
@danderson @astrid let's thank the gods of economical efficiency everyday
it doesn't seem like the chaotic attacker that could be so meticulous to target all distros and be stealthy as fucked has appeared *or* we didn't detect it