week6 - xz utils exploit
Crazy news last week about the new xz utils exploit. It was fun to keep track of developments as more news came out.
If you don't know or haven't heard, I'm not really the one to tell you. Look for videos on youtube for an explanation of what went down. But I can try a little.
Basically an open source project that many distributions of linux rely on for compression, particularly with SSH (and thus root level access) called xz utils, was compromised. A microsoft software engineer found it by running benchmark tests and notices that his ssh connections were half a second slower than usual. What kind of luck is that??? Shows the importance of establishing benchmarks and keeping an eye on them over time I suppose.
The exploit was made possible due to a little social engineering that took place in 2021. The project maintainer was burnt out, doing all the work, getting no pay or appreciation. A random contributor popped up who was willing to help, and throughout the course of the last couple years took over fully as the main caretaker. They released the last couple patches, and those are the ones that allow him to have root access to any computer utilizing these tools. The community was flabbergasted but honestly, and I'm sure many people feel this way, how could we not have seen this coming. The open source community operates on a level of pretty deep trust in each other, but those days might be over.
Its still the wild wild west out there. Might be safer to stick with Windows for now. Kind of ironic that the person who found it works for Microsoft.
Comments
Post a Comment