this post was submitted on 07 Apr 2024
5 points (69.2% liked)

Security

5021 readers
1 users here now

Confidentiality Integrity Availability

founded 5 years ago
MODERATORS
 

The XZ Utils backdoor, discovered last week, and the Heartbleed security vulnerability ten years ago, share the same ultimate root cause. Both of them, and in fact all critical infrastructure open source projects, should be fixed with the same solution: ensure baseline funding for proper open source maintenance.

top 1 comments
sorted by: hot top controversial new old
[–] [email protected] 3 points 7 months ago

That's a hell of a stretch of same root cause. Funding wouldn't prevent bad actors from slipping in vulnerabilities into commits.