Thought this was a good read exploring some how the “how and why” including several apparent sock puppet accounts that convinced the original dev (Lasse Collin) to hand over the baton.

  • hatedbad@lemmy.sdf.org
    link
    fedilink
    English
    arrow-up
    16
    arrow-down
    8
    ·
    3 months ago

    open source software getting backdoored by nefarious committers is not an indictment on closed source software in any way. this was discovered by a microsoft employee due to its effect on cpu usage and its introduction of faults in valgrind, neither of which required the source to discover.

    the only thing this proves is that you should never fully trust any external dependencies.