TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

Backdoor in XZ Utils That Almost Happened

19 点作者 room505大约 1 年前

4 条评论

geoelectric大约 1 年前
I find it unfortunate that Schneier chose to underline the XZ maintainer’s mental health issues (literally—he linkified it) as the reason he’d slowed down on the project, which then led to being open to taking on the malicious co-maintainer.<p>Schneier then follows that linkified fact up immediately with a parenthetical that Collin isn’t to blame. But then why call out that very potentially stigmatic thing at all, with sources to boot?<p>That explanatory note from Collin was buried in a mailing list and was at most a footnote to this story. Now it’s going to be part of the public accounting pushed by a famous security pundit with international reach, and with very little other context given to mitigate.<p>Either Schneier was trying to make a point of some kind, in which case he sure wheedled around it, or he should’ve been considerably more careful with essentially the <i>only</i> personal fact he chose to highlight about Collin. Either way, I’m disappointed.
评论 #40008425 未加载
评论 #40008479 未加载
ChrisMarshallNY大约 1 年前
<i>&gt; The market economy rewards this sort of insecurity.</i><p>That&#x27;s the money quote, right there. As long as people are willing to pay for shit, there will be people willing to produce and sell shit.<p>Why bother doing due diligence, if skipping it, means an extra lambo in the garage?
jijji大约 1 年前
changing the code by one character making it have an int overflow would have been more elegant.... no and the reason I even bring this point up is in early days of hacking into developers machines sometimes you find unpublished integer overflow exploits...
评论 #40008386 未加载
1vuio0pswjnm7大约 1 年前
&quot;Everything you use contains dozens of these libraries: some commercial, some open source and freely available.&quot;<p>&quot;Everything&quot;. Really. I use numerous programs that do not &quot;contain dozens of libraries&quot;.<p>How could he improve the sentence. Perhaps something like<p>&quot;Many programs link to dozens of these libraries...&quot;<p>&quot;Everything most people use contains dozens of these libraries...&quot;<p>And so on.<p>I am typing this comment in textmode using a text-only browser that is statically-linked to less than five libraries, including libc. I&#x27;m not using any commercial libraries. I have no idea what comprises &quot;everything&quot; anyone reading it is using or whether each of those things is linked to &quot;dozens of libraries&quot;. How would I. And neither does this author.<p>How difficult is it for an author to verify the accuracy of each sentence in an article. Perhaps it is more difficult when you rely on software developers as sources and they tell you a story full of hyperbole, exaggeration and biased, selective disclosure of facts.<p>The article in japantimes.co.jp someone submitted was absolutely cringeworthy.
评论 #40008630 未加载