Skip to content

Comment on XZ: Repo maintainer Lasse Collin responding on LKMLparent

Comments

high security packages like this that effect ssh and main parts of the OS critical for security and safety should be maintained by actual enterprises not by one developer.

I don’t remember the company names, but I guess people will remember the incidents.

- Solarwinds have been breached end to end.

- A company has been bribed (forced?) to ship backdoored encryption algorithms.

- A network hardware supplier’s firmware had been backdoored by Chinese IIRC.

- NSA backdoored national standards.

- Microsoft has been breached end to end.

In short, even if you’re a company, you’re one NSL, one bad actor, one misstep away from “total pwnage”.

I trust some individuals for developing critical software than entire “enterprise”s.

Everything is as strong as their weakest link.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.