The XZ Utils backdoor, discovered last week, and the Heartbleed security vulnerability ten years ago, share the same ultimate root cause. Both of them, and in fact all critical infrastructure open source projects, should be fixed with the same solution: ensure baseline funding for proper open source maintenance.\n
I got into a rabbit hole and read the story of the SolarWinds attack. Even as a total layman, what a rollercoaster.
@Hadriscus I wonder if anyone at SolarWinds or Mandiant would notice a 300ms delay. They didn’t even find it in June after the FBI contacted them.
Looks like passionate people working on open source projects are more reliable as watch dogs
Thanks