Kaspersky analysis of the backdoor in XZ

lemmyreader@lemmy.ml to Linux@lemmy.ml – 82 points –
Kaspersky analysis of the backdoor in XZ
web.archive.org
19

You are viewing a single comment

Ngl kaspersky is the close to the last group I care to hear from about security

https://www.techopedia.com/news/kasperskys-us-ban-a-long-history-of-espionage-kgb-nsa-and-edward-snowden

Well, it doesn't invalidate the analysis.

This was a sophisticated attack happening over 2 years, from knowing the current maintainer was emotionally vulnerable to the structure of using the build system to introduce the patched code to Linux distro repos.

I'm guessing Kaspersky will come to the same conclusions many others have; that this was a state actor or similiarly well heeled group.

1 more...