Artwork

Innehåll tillhandahållet av Nice Segue, LLC, Brad Shoemaker, and Will Smith. Allt poddinnehåll inklusive avsnitt, grafik och podcastbeskrivningar laddas upp och tillhandahålls direkt av Nice Segue, LLC, Brad Shoemaker, and Will Smith eller deras podcastplattformspartner. Om du tror att någon använder ditt upphovsrättsskyddade verk utan din tillåtelse kan du följa processen som beskrivs här https://sv.player.fm/legal.
Player FM - Podcast-app
Gå offline med appen Player FM !

230: Maybe Gentoo Was Right All Along

1:01:57
 
Dela
 

Manage episode 412522377 series 2544285
Innehåll tillhandahållet av Nice Segue, LLC, Brad Shoemaker, and Will Smith. Allt poddinnehåll inklusive avsnitt, grafik och podcastbeskrivningar laddas upp och tillhandahålls direkt av Nice Segue, LLC, Brad Shoemaker, and Will Smith eller deras podcastplattformspartner. Om du tror att någon använder ditt upphovsrättsskyddade verk utan din tillåtelse kan du följa processen som beskrivs här https://sv.player.fm/legal.

This week we attempt to unpack the recent, historic security breach in the open source world, after the discovery of a secret backdoor that was inserted by a malicious actor into the the xz-utils package, with a focus on which specific Linux distros were targeted and why, how the attacker socially engineered their way into the position of authority that made this possible, and what ought to be done to support developers of critical infrastructure to (hopefully) prevent this from happening again.

Show notes for this episode: https://tinyurl.com/techpod-230-xz-backdoor

Go watch Pirates of Silicon Valley for an upcoming episode where we'll discuss it: https://archive.org/details/piratesofsiliconvalley_201908

Support the Pod! Contribute to the Tech Pod Patreon and get access to our booming Discord, a monthly bonus episode, your name in the credits, and other great benefits! You can support the show at: https://patreon.com/techpod

  continue reading

270 episoder

Artwork
iconDela
 
Manage episode 412522377 series 2544285
Innehåll tillhandahållet av Nice Segue, LLC, Brad Shoemaker, and Will Smith. Allt poddinnehåll inklusive avsnitt, grafik och podcastbeskrivningar laddas upp och tillhandahålls direkt av Nice Segue, LLC, Brad Shoemaker, and Will Smith eller deras podcastplattformspartner. Om du tror att någon använder ditt upphovsrättsskyddade verk utan din tillåtelse kan du följa processen som beskrivs här https://sv.player.fm/legal.

This week we attempt to unpack the recent, historic security breach in the open source world, after the discovery of a secret backdoor that was inserted by a malicious actor into the the xz-utils package, with a focus on which specific Linux distros were targeted and why, how the attacker socially engineered their way into the position of authority that made this possible, and what ought to be done to support developers of critical infrastructure to (hopefully) prevent this from happening again.

Show notes for this episode: https://tinyurl.com/techpod-230-xz-backdoor

Go watch Pirates of Silicon Valley for an upcoming episode where we'll discuss it: https://archive.org/details/piratesofsiliconvalley_201908

Support the Pod! Contribute to the Tech Pod Patreon and get access to our booming Discord, a monthly bonus episode, your name in the credits, and other great benefits! You can support the show at: https://patreon.com/techpod

  continue reading

270 episoder

Alla avsnitt

×
 
Loading …

Välkommen till Player FM

Player FM scannar webben för högkvalitativa podcasts för dig att njuta av nu direkt. Den är den bästa podcast-appen och den fungerar med Android, Iphone och webben. Bli medlem för att synka prenumerationer mellan enheter.

 

Snabbguide