this post was submitted on 31 Mar 2024
156 points (100.0% liked)

Open Source

823 readers
20 users here now

All about open source! Feel free to ask questions, and share news, and interesting stuff!

Useful Links

Rules

Related Communities

Community icon from opensource.org, but we are not affiliated with them.

founded 5 years ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
[–] 0xtero 22 points 7 months ago (1 children)

I don't think this one counts as a big win to be honest It was just freakish luck

[–] BestBouclettes@jlai.lu 13 points 7 months ago (2 children)

It's definitely freakish luck but at least it got found out. A closed source software would have gone through unnoticed.

[–] vrighter@discuss.tchncs.de 11 points 7 months ago

the fact that it was found by luck, not methodically, to me implies that there probably are other backdoors we didn't get lucky with.

[–] 0xtero 6 points 7 months ago

Or found out in corporate code review / pentest. We just don't know. I get that we want to say FOSS is great due to the "many eyes/shallow bugs" thing, but that didn't work for OpenSSL or log4j. The fact that it did now is great, but let's not get carried away. It was just pure luck.