this post was submitted on 30 Mar 2024
1578 points (97.7% liked)

linuxmemes

20901 readers
1915 users here now

I use Arch btw


Sister communities:

Community rules

  1. Follow the site-wide rules and code of conduct
  2. Be civil
  3. Post Linux-related content
  4. No recent reposts

Please report posts and comments that break these rules!

founded 1 year ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
[–] [email protected] 197 points 6 months ago (2 children)

To be fair, we only know of this one. There may well be other open source backdoors floating around with no detection. Was heartbleed really an accident?

[–] [email protected] 100 points 6 months ago (1 children)

True. And the "given enough eyeballs, all bugs are shallow" is a neat sounding thing from the past when the amount of code lines was not as much as now. Sometimes it is scary to see how long a vulnerability in the Linux kernel had been there for years, "waiting" to be exploited.

[–] [email protected] 73 points 6 months ago (2 children)

Still far better than a proprietary kernel made by a tech corp, carried hardly changed from release to release, even fewer people maintain, and if they do they might well be adding a backdoor themselves for their government agency friends.

[–] [email protected] 19 points 6 months ago

true, opensource can be flawed, but it's certain less flawed than a closed source alternatives

[–] [email protected] 8 points 6 months ago
[–] [email protected] 35 points 6 months ago

Yeah he didn't find the right unmaintained project. There are many many many cs undergrads starting projects that will become unmaintained pretty soon.