this post was submitted on 07 Apr 2024
96 points (98.0% liked)

Open Source

31725 readers
167 users here now

All about open source! Feel free to ask questions, and share news, and interesting stuff!

Useful Links

Rules

Related Communities

Community icon from opensource.org, but we are not affiliated with them.

founded 5 years ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
[–] [email protected] 9 points 8 months ago* (last edited 8 months ago) (1 children)

It was a huge fluke of luck that the XZ backdoor didn’t go in any actual Linux distribution releases.

It did get into a few, just not the ones corporations are likely to be using.

[–] DetectiveSanity 10 points 8 months ago (1 children)

I doubt it would have been discovered this fast and easily if it was closed source.

[–] [email protected] 14 points 8 months ago (1 children)

it's safe to assume there are similar issues in closed source. A big part of the snowden leaks was about how NSA could access lots of data at will. It wouldn't surprise me if they also could execute code.

Also there is stuxnet. But I am not sure, if there were intentional backdoors, or only some "natural occuring" RCE.

[–] Kelly 7 points 8 months ago

It wouldn't surprise me if they also could execute code.

They sat on external blue for 5 year before it was stolen and they disclosed the vulnerability to Microsoft.

https://en.wikipedia.org/wiki/EternalBlue

I don't see why we wouldn't assume there is always something similar in their armoury.