Picture Me Coding

The XZ Apocalypse

April 10, 2024 Erik Aker and Mike Mull Season 2 Episode 30
The XZ Apocalypse
Picture Me Coding
More Info
Picture Me Coding
The XZ Apocalypse
Apr 10, 2024 Season 2 Episode 30
Erik Aker and Mike Mull

A week ago a developer in San Francisco named Andres Freund found a backdoor in SSH which would grant some shadowy figure access to Linux machines running the latest version of a library called liblzma.  Even more incredibly, there were various semi-anonymous figures clamoring for inclusion of this compromised version of liblzma into the latest version of various Linux distros. 

This entire scheme had been underway for over three years before it fell apart under Freund's scrutiny and attention from the broader software industry.

This week Mike gives us a breakdown of the exploit and we talk about the fallout from this backdoor which took advantage of an overworked and vulnerable open-source maintainer. 

As Mike puts it, the story is "bonkers".

To read more about it, check out these articles: 


Show Notes

A week ago a developer in San Francisco named Andres Freund found a backdoor in SSH which would grant some shadowy figure access to Linux machines running the latest version of a library called liblzma.  Even more incredibly, there were various semi-anonymous figures clamoring for inclusion of this compromised version of liblzma into the latest version of various Linux distros. 

This entire scheme had been underway for over three years before it fell apart under Freund's scrutiny and attention from the broader software industry.

This week Mike gives us a breakdown of the exploit and we talk about the fallout from this backdoor which took advantage of an overworked and vulnerable open-source maintainer. 

As Mike puts it, the story is "bonkers".

To read more about it, check out these articles: