The XZ Utils backdoor, discovered last week, and the Heartbleed security vulnerability ten years ago, share the same ultimate root cause. Both of them, and in fact all critical infrastructure open source projects, should be fixed with the same solution: ensure baseline funding for proper open source maintenance.

  • Toes♀
    link
    fedilink
    English
    arrow-up
    1
    arrow-down
    6
    ·
    7 months ago

    Isn’t that why boringSSL was created? I wonder if we’ll see corpo forks of openSSH soon