Comment on How no-techy/"common" people know if a Open Source code is secure?

<- View Parent
adespoton@lemmy.ca ⁨1⁩ ⁨week⁩ ago

For a good case study: en.wikipedia.org/wiki/XZ_Utils_backdoor

If this had been closed source, the attacker would not have been able to use the technique to commit the changes in the first place.

However, if they HAD snuck the changes in, nobody would have caught them, and only the developer would have been able to identify something was wrong before full deployment.

But we should all assume that while the xz trojan never made it out, others likely have, both in open and closed source.

source
Sort:hotnewtop