How a malicious backdoor in XZ Utils threatened the Internet ecosystem
How a malicious backdoor in XZ Utils threatened the Internet ecosystem
TL;DW:A video by Veritasium about how a single dependency (.xz) was momentarily compromised leading to the compromise of OpenSSH (which uses .xz as a dependency), which ultimately would have spelled out a master key access to Linux systems across the world.
Really cool how they explain and visualize LZ, Deflate, LZMA and RSA.
Shout-out to all the Open Source contributors out there! And a reminder to others to show your appreciation to those who dedicate time and resources to projects that often go unappreciated or for granted.