• 0 Posts
  • 36 Comments
Joined 1 year ago
cake
Cake day: June 10th, 2023

help-circle

  • underisk@lemmy.mltoLinux@lemmy.mlXZ backdoor in a nutshell
    link
    fedilink
    arrow-up
    28
    arrow-down
    1
    ·
    3 months ago

    I think ideas about prevention should be more concerned with the social engineering aspect of this attack. The code itself is certainly cleverly hidden, but any bad actor who gains the kind of access as Jia did could likely pull off something similar without duplicating their specific method or technique.



















  • Once again, their adherence to the letter of the GPL is certainly up for debate, I said as much at the start.

    Their violation of its intent, however, is not. They are putting up roadblocks, however trivial or insignificant you seem to believe they are, to limit your freedom in redistributing they code they are providing. Period. This controversy would not exist if they weren’t.