Today marks the 10th anniversary of the Heartbleed vulnerability in OpenSSL, which had the same ultimate root cause as recent XZUtils backdoor incident (dev.to)
from otto@programming.dev to technology@lemmy.ml on 07 Apr 2024 20:51
https://programming.dev/post/12487523

The XZ Utils backdoor, discovered last week, and the Heartbleed security vulnerability ten years ago, share the same ultimate root cause. Both of them, and in fact all critical infrastructure open source projects, should be fixed with the same solution: ensure baseline funding for proper open source maintenance.

#technology

threaded - newest

breakingcups@lemmy.world on 07 Apr 2024 22:17 next collapse

Fuck me, ten years already?

Turbo@lemmy.ml on 08 Apr 2024 01:47 collapse

Thinking the same thing. WTF

darkpanda@lemmy.ca on 09 Apr 2024 00:57 next collapse

I wouldn’t say quite the same root cause — the xz back door was clearly intentional, but I don’t recall the Heartbleed bug having been intentional, and developer responsible has denied allegations to that effect. There can be no doubt in the xz case of malicious intent.

Ptsf@lemmy.world on 12 Apr 2024 00:54 collapse

Hear me out. What if instead we just included a respected developers open-source project into our multi billion dollar product, paid them nothing, and gave them the pressure of ensuring it’s working for millions of users at the threat of their reputation until their mental health is in shambles? 🤔