Did One Guy Just Stop a Huge Cyberattack?
Did One Guy Just Stop a Huge Cyberattack?

Did One Guy Just Stop a Huge Cyberattack?

Did One Guy Just Stop a Huge Cyberattack?
Did One Guy Just Stop a Huge Cyberattack?
I suspect this was just a lucky catch of shit that happens all the time. Supply chain attacks are super scary and effectively impossible to eliminate in modern software development.
Obviously not impossible, just the best reason for open source software
It's almost impossible to spot by people looking directly at the code. I'm honestly surprised this one was discovered at all. People are still trying to deconstruct this exploit to figure out how the RCE worked.
And supply chain attacks are effectively impossible to eliminate as an attack vector by a developer-user of a N-level dependency. Not having dependencies or auditing every dependency is unreasonable in most cases.
So, Microsoft saved everyone from the bad Linux then?
/s
"Linux saved itself."
You're late to the party NYT.
Also, dude made a good save. Only arch users got hit lol
The hack mainly targeted Debian and fedora
But on Debian it only shipped on sid. This is the reason for Debians slow as fuck release cycle
Arch didn't patch it with systemd so it didn't really affect them afaik. It did hit OpenSUSE Tumbleweed users.
Do you know the exploit was detected in Debian Sid? (by a PostgreSQL
developer), Arch got the update (with both compromised versions), but because don't directly link openssh
to liblzma
(as Debian), and thus this attack vector is not possible.
Also, other rolling distros also got the compromised versions, maybe: openSUSE Tumbleweed, Endeavour OS, Fedora Rawhide, Slackware -current, etc.
There was some checking in the exploit to verify that it was being built for a deb or rpm package, it didn't build for anything else. Also, the way the exploit was loaded at runtime relied on features of systemd that Arch isn't using. It was a dud on Arch.
nothing of value was lost
A picture of the man
Yuuuuuuup. We all owe this man beer for life.
It felt like it had a bit of sensationalism, which alas is not uncommon in today's journalism, but can it be too much that a major newspaper like the NYT covering this story can bring indirect attention to the problem of hugely underpaid/no paid people working on (and mantaining) critical FOSS stuff?
They did claim his work is “boring to tears” right after saying it was “thankless”. What a condescending piece of shit journalist.
Yes
"Engineers have been circulating an old, famous-among-programmers web comic about how all modern digital infrastructure rests on a project maintained by some random guy in Nebraska. (In their telling, Mr. Freund is the random guy from Nebraska.)"
That's not quite right. Lasse Collin is the random guy in Nebraska. Freund is the guy that noticed the whole thing was about to topple.
and that one guy (Lasse) was burnt out and pressured [by jia?] to step back and let jia be the person that the whole internet infrastructure relied upon
Publicly pressured by sock puppets. You can see some rando doing similar in repositories for projects like Avahi.