Today marks the 10th anniversary of the Heartbleed vulnerability in OpenSSL, which had the same ultimate root cause as recent XZUtils backdoor incident
(medium.com)
from [email protected] to [email protected] on 07 Apr 2024 18:56
https://programming.dev/post/12487684
from [email protected] to [email protected] on 07 Apr 2024 18:56
https://programming.dev/post/12487684
The XZ Utils backdoor, discovered last week, and the Heartbleed security vulnerability ten years ago, share the same ultimate root cause. Both of them, and in fact all critical infrastructure open source projects, should be fixed with the same solution: ensure baseline funding for proper open source maintenance.
#security
threaded - newest
That’s a hell of a stretch of same root cause. Funding wouldn’t prevent bad actors from slipping in vulnerabilities into commits.