Skip to content

Commit

Permalink
post(xz): added conclusion
Browse files Browse the repository at this point in the history
  • Loading branch information
himazawa committed Mar 31, 2024
1 parent 49ed5a4 commit 6ddeda4
Showing 1 changed file with 8 additions and 0 deletions.
8 changes: 8 additions & 0 deletions content/posts/xz-backdoor/index.en.md
Original file line number Diff line number Diff line change
Expand Up @@ -157,6 +157,14 @@ This is a controversial topic because there are projects that are maintained by
### Recursive controls
The project you are including will probably also have dependencies, make sure the same scrutiny is applied by the project maintainers on their supply chain to avoid indirect compromission.

## Conclusion
The `xz` backdoor is yet another case of supply chain hijacking, but this time with way more complexity and effort behind it.

We shound't blame the current maintainer or the Open Source software: issues like that (intentional or not) are mostly unpatchable because they leverage the human factor that is inreplaceable.

On the other hand we can follow some best practices in picking software to integrate inside our repositories to reduce the chance of this from happening.


## Resources

- OSS-Security List: https://www.openwall.com/lists/oss-security/2024/03/29/4
Expand Down

0 comments on commit 6ddeda4

Please sign in to comment.