← Back to context

Comment by gregsadetsky

5 days ago

This was exactly the playbook that led to the xz backdoor.

Just the quotes:

https://en.wikipedia.org/wiki/XZ_Utils_backdoor

Yes, I had that in mind too.

Its worth any maintainer to be familiar with these methods to build up defences. With a few sock puppet accounts a single person could do it on their spare time. A nation state or criminal full time enterprise could do several attacks.

It's scary and immoral but I find it fascinating too. Like the dark side of the how to win friends books.

Security.