A backdoor in xz
A backdoor in xz
Posted Mar 30, 2024 1:29 UTC (Sat) by bluca (subscriber, #118303)In reply to: A backdoor in xz by jengelh
Parent article: A backdoor in xz
Of course by itself it doesn't prove that the software is not malicious, how could it? That's not the point, the point is increasing auditability. A commit in a repository is eminently auditable, while random stuff getting injected from a developer's machine in a tarball after the fact, before publishing, is not.
