logoalt Hacker News

vsgherziyesterday at 9:59 PM2 repliesview on HN

Even linux was subjected to an attack in xz utils. Granted it is much harder and they have a much better auditing problem (something npm should learn from). There really isn't a silver bullet here unfortunately. The industry as a whole needs to get more serious about this.


Replies

nine_kyesterday at 10:02 PM

There's no silver bullet, but getting an exploit into xz took extraordinary effort, a long time, and bespoke code, because it needed to slip under the radar of actual humans reading the code. A shai hulud-style attack won't work with any reasonable Linux distro, like it does with npm.

kelvinjps10today at 12:45 AM

but it was caught with the existing release model, where first it goes to testing where many people before reaching the production systems in the stable release. for example debian