this post was submitted on 02 Apr 2024
469 points (94.3% liked)

Programmer Humor

35028 readers
70 users here now

Post funny things about programming here! (Or just rant about your favourite programming language.)

Rules:

founded 5 years ago
MODERATORS
 
you are viewing a single comment's thread
view the rest of the comments
[–] [email protected] 70 points 1 year ago* (last edited 1 year ago) (2 children)

The only reason why xz got exposed was because someone noticed SSH was a bit slower and decided to take it to their own hands to investigate. It’s possible this backdoor would go unnoticed for far longer if the attacker didn’t make this slight oversight.

So it might be that there have been other, successful attacks before. It’s just that this one is the one that got exposed.

[–] [email protected] 69 points 1 year ago (1 children)

Slower as in 500ms slower iirc.

Linux users when bloat

[–] [email protected] 56 points 1 year ago (1 children)

tbh given the context 500ms is a lot.

[–] [email protected] 21 points 1 year ago (1 children)

Yeah. 500ms for ssh feels like an eternity.

[–] [email protected] 7 points 1 year ago

SSHing into my less powerful machines takes a good few seconds, so I'm not sure if I'd notice an extra 500ms. For the more powerful ones that are basically instant it would be much more noticeable.