DiscoverTechnology PillThe XZ exploit: The day the internet got lucky
The XZ exploit: The day the internet got lucky

The XZ exploit: The day the internet got lucky

Update: 2024-07-27
Share

Description

This week we're talking about a backdoor inserted into a popular Linux file compression tool, which had the potential to massively undermine the security of vast swathes of the internet. What happened? How did it happen? And how was it thwarted?




Links


- Andres Freund's Mastodon - where he revealed the backdoor: https://mastodon.social/@AndresFreundTec


- Read more in Ars Technica's article about it: https://arstechnica.com/security/2024/03/backdoor-found-in-widely-used-linux-utility-breaks-encrypted-ssh-connections/
- Read more in the verge's article about it https://www.theverge.com/2024/4/2/24119342/xz-utils-linux-backdoor-attempt
- Read more in Wired's article about it https://www.wired.com/story/jia-tan-xz-backdoor/
- Check out this excellent and very helpful diagram: https://twitter.com/fr0gger_/status/1775759514249445565
- The XKCD comic we mention: https://xkcd.com/538/

Comments 
00:00
00:00
x

0.5x

0.8x

1.0x

1.25x

1.5x

2.0x

3.0x

Sleep Timer

Off

End of Episode

5 Minutes

10 Minutes

15 Minutes

30 Minutes

45 Minutes

60 Minutes

120 Minutes

The XZ exploit: The day the internet got lucky

The XZ exploit: The day the internet got lucky

Privacy International