First, the problem is the reputation hit and the trust going away. Right now on Hacker News 2 maybe 3 of the posts on front page have been about this since the news broke out. Also when trust goes away, its very hard to come back.
Secondly, the main problem that I see is how many other backdoors/dependencies are vulnerable that we might not know? They might not have performance issues. Also if this went unnoticed, in the long term it might have found its way and actually compromised people. I’m glad this was taken care of and no one was compromised.
OpenSSH is developed by the OpenBSD project and I have a lot more confidence in them than in any random "enterprise".
The issue in this case is that Linux distros took it upon themselves to alter its code base by linking in libsystemd (thus also liblzma) for the dubious benefit of better systemd integration, which comes with a generous helping of attack surface.
Comments
First, the problem is the reputation hit and the trust going away. Right now on Hacker News 2 maybe 3 of the posts on front page have been about this since the news broke out. Also when trust goes away, its very hard to come back. Secondly, the main problem that I see is how many other backdoors/dependencies are vulnerable that we might not know? They might not have performance issues. Also if this went unnoticed, in the long term it might have found its way and actually compromised people. I’m glad this was taken care of and no one was compromised.
Is there some implied proposal I missed?
https://news.ycombinator.com/item?id=39904034
OpenSSH is developed by the OpenBSD project and I have a lot more confidence in them than in any random "enterprise".
The issue in this case is that Linux distros took it upon themselves to alter its code base by linking in libsystemd (thus also liblzma) for the dubious benefit of better systemd integration, which comes with a generous helping of attack surface.