The Internet Was Weeks Away From Disaster And No One Knew
A video on YouTube. In Science & Engineering, a Krater category.
Watch on YouTubeSummary by Krater
An explainer detailing how the XZ Utils supply chain attack was discovered, how the backdoor was engineered using data compression and SSH authentication bypasses, and the wider implications for open-source software security.
From the video
Answers: How did the XZ Utils backdoor work and how was it discovered?
- XZ Utils supply chain attack
- OpenSSH backdoor
- data compression algorithms
- RSA authentication and GOT hooking
- open-source software maintenance
What it concludes
- Most top supercomputers, servers, banks, and governments run Linux infrastructure.
- XZ compression can shrink files to about 70% of the size of a typical .zip file.
- The XZ backdoor successfully bypassed RSA authentication by hijacking the Global Offset Table (GOT) and using IFunc resolvers.
- Andres Freund discovered the XZ backdoor by noticing a small slowdown in connection times while testing PostgreSQL.
Rate it, review it and add it to your lists in Krater.
Titles and thumbnails from YouTube. Krater isn't affiliated with, endorsed by or sponsored by YouTube or Google.