this post was submitted on 02 Apr 2024
468 points (94.3% liked)

Programmer Humor

38614 readers
54 users here now

Post funny things about programming here! (Or just rant about your favourite programming language.)

Rules:

founded 6 years ago
MODERATORS
 
you are viewing a single comment's thread
view the rest of the comments
[–] BestBouclettes@jlai.lu 114 points 2 years ago (3 children)

There are two types of backdoors, the ones that were fixed and the ones we don't know about.

[–] magic_lobster_party@kbin.run 70 points 2 years ago* (last edited 2 years ago) (2 children)

The only reason why xz got exposed was because someone noticed SSH was a bit slower and decided to take it to their own hands to investigate. It’s possible this backdoor would go unnoticed for far longer if the attacker didn’t make this slight oversight.

So it might be that there have been other, successful attacks before. It’s just that this one is the one that got exposed.

[–] scarilog@lemmy.world 69 points 2 years ago (1 children)

Slower as in 500ms slower iirc.

Linux users when bloat

[–] imnotfromkaliningrad@lemmy.ml 56 points 2 years ago (1 children)

tbh given the context 500ms is a lot.

[–] nickwitha_k@lemmy.sdf.org 21 points 2 years ago (1 children)

Yeah. 500ms for ssh feels like an eternity.

[–] LazaroFilm@lemmy.world 25 points 2 years ago (2 children)

And the ones you leave for yourself to check during development and forgotten to close before release.

[–] BestBouclettes@jlai.lu 11 points 2 years ago

Shhh we don't talk about these !

[–] redcalcium@lemmy.institute 6 points 2 years ago (1 children)

This is why you should secure your own bureaucracy-bypassing backdoor with a long ass key (bonus point if you use pki instead of a simple static key).

[–] LazaroFilm@lemmy.world 3 points 2 years ago

I just use the Konami code as a secret password.

[–] knorke3@lemm.ee 13 points 2 years ago

don't forget the ones we got paid for very well and the ones we introduced to not go to prison