A backdoor in xz
A backdoor in xz
Posted Mar 30, 2024 1:37 UTC (Sat) by bluca (subscriber, #118303)In reply to: A backdoor in xz by bkw1a
Parent article: A backdoor in xz
> It seems to me that distributions shouldn't be modifying a critical piece of security infrastructure like sshd. Isn't that just asking for trouble?
No, it isn't, you are missing the wood for the trees. It's normal for distributions to patch core components - pick any distro and look at their kernel, gcc or glibc packages and you'll find tons of patches. The issue here is that a combination of archaic release practices (make-dist tarball generated who-knows-where-by-whom) and very sophisticated attack almost caused a disaster, essentially because of a lack of supply chain security.
