• Wes_Dev@lemmy.ml
    link
    fedilink
    arrow-up
    54
    ·
    6 months ago

    Let’s keep in mind that if this is a state actor or some sort of global organized crime, then they don’t put all their eggs into one basket. If that’s the case, they’re going to have a bunch of other plans and backdoor attempts ongoing. This isn’t the end and we can assume there’s something else somewhere that went unnoticed.

    Security is a constantly changing war of attrition, not a goal/product/configuration.

  • BestBouclettes@jlai.lu
    link
    fedilink
    arrow-up
    21
    arrow-down
    3
    ·
    6 months ago

    If anything it highlights how great open source actually is when it comes to security. People saw it and immediately flagged it.

  • delirious_owl@discuss.online
    link
    fedilink
    arrow-up
    12
    arrow-down
    3
    ·
    6 months ago

    Lost me at suggesting that we run EDR on prod Linux servers.

    Literally installing a backdoor intentionally…wow

  • tux@lemmy.world
    link
    fedilink
    arrow-up
    4
    ·
    6 months ago

    Wish I could be a fly on the walk when the bad actor realized years of work has just gone down the drain

    • pivot_root@lemmy.world
      link
      fedilink
      arrow-up
      7
      arrow-down
      2
      ·
      6 months ago

      Probably fear, then subsequently followed by their brains next to you on said wall. Whichever government paid for a multi-year campaign to backdoor enterprise Linux distributions is not going to be happy about this failure.

  • NocturnalMorning@lemmy.world
    link
    fedilink
    arrow-up
    5
    arrow-down
    2
    ·
    6 months ago

    What a dick. I couldn’t imagine spending that much time contributing to a project so I could introduce security vulnerabilities.

    If this is one individual, and not a nation state, somebody needs to make some friends and pick up some hobbies.

    • breadsmasher@lemmy.world
      link
      fedilink
      English
      arrow-up
      11
      ·
      edit-2
      6 months ago

      I think its more likely someone spent this time contributing to the project specifically to exploit it

      • NocturnalMorning@lemmy.world
        link
        fedilink
        arrow-up
        1
        ·
        6 months ago

        Yeah, I got that. I’m saying they need to make some friends and get some hobbies if they aren’t being funded by a state.