Skip to content

Security Researchers Find XZ Utils Backdoored Debian Images on Docker Hub

news.itsfoss.com
13 points65812 comments
On HN

Comments

"The Debian development team put it like this: So, given the wafer thin vectors of attack here, the extreme age of the images in question, and the fact that even at the time that they were fresh, they were images that shouldn't be used in production anyhow (Debian's "development" repositories), we've opted to leave them in place.

Binarly kind of agrees ... "

Good to know that the Debian team's attitude towards security has not materially changed since the OpenSSL fiasco.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.