Spyke

Syndicated from the fediverse. Read and engage on the original instance.

View original on programming.dev
technology·TechnologybyOtto

Today marks the 10th anniversary of the Heartbleed vulnerability in OpenSSL, which had the same ultimate root cause as recent XZUtils backdoor incident

The XZ Utils backdoor, discovered last week, and the Heartbleed security vulnerability ten years ago, share the same ultimate root cause. Both of them, and in fact all critical infrastructure open source projects, should be fixed with the same solution: ensure baseline funding for proper open source maintenance.

Today marks the 10th anniversary of the Heartbleed vulnerability in OpenSSL, which had the same ultimate root cause as recent XZUtils backdoor incidenthttps://dev.to/ottok/heartbleed-and-xz-backdoor-learnings-open-source-infrastructure-can-be-improved-efficiently-with-moderate-funding-5542Open linkView original on programming.dev
76

4 replies

I wouldn’t say quite the same root cause — the xz back door was clearly intentional, but I don’t recall the Heartbleed bug having been intentional, and developer responsible has denied allegations to that effect. There can be no doubt in the xz case of malicious intent.

8

Hear me out. What if instead we just included a respected developers open-source project into our multi billion dollar product, paid them nothing, and gave them the pressure of ensuring it's working for millions of users at the threat of their reputation until their mental health is in shambles? 🤔

1

You reached the end