Reported by:

lol. Nice meme.

125
Jump in the discussion.

No email address required.

Is there an article i can read on this

Jump in the discussion.

No email address required.

Inside the failed attempt to backdoor SSH globally — that got caught by chance

Nobody else had raised concerns, and I don't believe any existing security tooling or processes would have caught this (I realise there will be a torrent of vendors claiming they detect this… but they will detect this now that somebody told them).

Because Andres privately researched the issue and got the Linux distributions to take it seriously, he averted this reaching any kind of wide (or even small) deployment in the real world.

Also, Andres had a unique testing environment and a set of coincidental setup issues which allowed him to discover the issue. I don't know of anybody else has this setup.

Jump in the discussion.

No email address required.

This seems to be the opposite of catching it by chance


https://i.rdrama.net/images/17092367509484937.webp https://i.rdrama.net/images/17093267613293715.webp https://i.rdrama.net/images/17151063782028813.webp

Jump in the discussion.

No email address required.

He wasn't doing security auditing, he's just an autismo mad that someone slowed down his postgres build rig or something.

Jump in the discussion.

No email address required.

Yeah. That kind of autism doesn't happen by chance. The normie journoscum just wants to degenerate this hard working nooticer


https://i.rdrama.net/images/17092367509484937.webp https://i.rdrama.net/images/17093267613293715.webp https://i.rdrama.net/images/17151063782028813.webp

Jump in the discussion.

No email address required.

>Without having seen the odd complaints in valgrind, I don't think I would have looked deeply enough when seeing the high cpu in sshd below _get_cpuid().”

To me, the biggest mindfrick of the whole thing is that he remembered seeing some valgrind warnings from like a goddarn year ago. :marseymindblown: I pretty much ignore all compiler warnings and forget any error message 15 seconds after I make it go away. This is why I'll never be a real autiste. :marseyitsover:

Jump in the discussion.

No email address required.

I forget error messages as I'm reading them tbh :marseyretardcheers:

Jump in the discussion.

No email address required.

Compilers warnings are just bugs that haven't happened to you yet.

Jump in the discussion.

No email address required.

Running any software I wrote is ruining your computer, even if it hasn't happened to you yet.

I write code with the same manic energy as when you let your sister play a fighting game, and she just mashes all the buttons at once and somehow wins.

Jump in the discussion.

No email address required.

:#tayadmire:

Jump in the discussion.

No email address required.

There :marseycheerup: are so many you just end up ignoring them since they usually are not important

Jump in the discussion.

No email address required.

Link copied to clipboard
Action successful!
Error, please refresh the page and try again.