TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

The xz backdoor thing reminds me of a story

176 pointsby luuabout 1 year ago

6 comments

jddjabout 1 year ago
I remember a few months ago there was a discussion[1] here about how fossil, the VCS for sqlite, should bring in a dependency on mermaid charts already.<p>Nothing against mermaid, but I guess supply chain attacks are hard to conceptualise until they happen. When we&#x27;re shortsighted we risk our mitigations against vague but serious threat models losing out against convenience.<p>[1]<a href="https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=38886344">https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=38886344</a>
评论 #39889510 未加载
评论 #39889008 未加载
dilyevskyabout 1 year ago
There’s someone commenting on the thread saying a background check will uncover an illegal agent. That’s cute
deathanatosabout 1 year ago
Most of the details are out there but …<p>&gt; <i>in that he had apparently downloaded a copy of everything</i><p>… is a day in the office? I&#x27;ve done this, particularly at places that are &quot;one repo == one project&quot; organized (i.e., <i>not</i> monorepo): e.g., if I make a breaking change to a library, I&#x27;m going to update all the uses of that. Still to this day, the easiest way to do that is locally, with command line tooling.
评论 #39891902 未加载
评论 #39890465 未加载
77pt77about 1 year ago
The next time something like this happens it will be a distribution packager (RedHat, arch, etc).<p>They&#x27;ll just release a package that has extra code than a clean build from source.
评论 #39891002 未加载
renewiltordabout 1 year ago
I don&#x27;t doubt that this happened, but if you use e-verify and fill in Form I-9 how does this happen? I&#x27;m in the middle of hiring an F-1 student on OPT and I need to look at his EAD and verify it&#x27;s not fake according to my lawyer. So I do. Nice and easy.
评论 #39888517 未加载
评论 #39888864 未加载
评论 #39888456 未加载
评论 #39888487 未加载
curiousgalabout 1 year ago
&gt; <i>None of his paychecks were ever cashed</i><p>I don&#x27;t understand this. People were paid by cheque in the early 2000s?
评论 #39888885 未加载
评论 #39888522 未加载
评论 #39888590 未加载
评论 #39888663 未加载
评论 #39888568 未加载
评论 #39888936 未加载
评论 #39888527 未加载
评论 #39889134 未加载
评论 #39888620 未加载