TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Technologist vs. spy: the xz backdoor debate

63 pointsby rbcabout 1 year ago

6 comments

trogdorabout 1 year ago
&gt;In other words, all signs point to this being a professional, for-pay operation — and it wouldn’t be surprising if it was paid for by a foreign government.<p>Or a not-foreign government…
评论 #39877080 未加载
bediger4000about 1 year ago
This is an interesting article. Zalewski is almost unique in the ability and credibility to write this. He used to work for Google in infosec, he&#x27;s got a lot of experience writing code, and he no longer works for a big corporation, so he&#x27;s free to say what he thinks.
colejohnson66about 1 year ago
More evidence that the OSS community needs to drop the “many eyes” theory of security
评论 #39877274 未加载
评论 #39878494 未加载
评论 #39879596 未加载
shnkrabout 1 year ago
&gt;The relationship with commercial vendors isn’t always healthy, but many major OSS projects are supported to a significant extent.<p>Almost always the so called &quot;community&quot; supporting a OSS project is an employee of a commercial vendor who is only interested as long as he is assigned to the project or task.<p>The solution is to have a full time owners and maintainers for all the critical projects and the government has to foot the bill. The govt can setup a division to identify such projects.
评论 #39877705 未加载
评论 #39876810 未加载
评论 #39877676 未加载
publius_0xf3about 1 year ago
&gt;In fact, here’s an interesting thought: perhaps they have known for a while. Would we be able to tell the difference between a carefully-timed disclosure — presumably engineered to conceal “methods and sources” — and a serendipitous discovery?
egberts1about 1 year ago
All that can be avoided by doing really good sets of unit tests and integration tests, then incorporate its test result into the validation part of the repository.
评论 #39876585 未加载
评论 #39877448 未加载