• sovietknuckles [they/them]@hexbear.net
    link
    fedilink
    English
    arrow-up
    0
    ·
    7 months ago

    “Hey, it’s totally cool that Microsoft GitHub blocked access to one of the repositories in the very center of the xz backdoor saga,” Michal Woźniak, a white hat hacker who was part of a team that discovered DRM in a Polish train earlier this year wrote on Mastodon. “It’s not like a bunch of people are scrambling to try to make sense of all the right now, or that specific commits got linked to directly from media and blogposts and the like. Cool, cool.”

    Security teams that break stuff to mitigate risk and call it fixed is exactly what Linus’s Do No Harm post is about.

    • jmcs@discuss.tchncs.de
      link
      fedilink
      arrow-up
      0
      ·
      7 months ago

      When your entire security model consists of obfuscation and sticking your head in the sand, sweeping the vulnerabilities under the proverbial rug is the obvious course of action.

    • twinnie@feddit.uk
      link
      fedilink
      arrow-up
      0
      ·
      7 months ago

      I’m sure anyone who really needs access can get to it. It’s not a surprise that MS don’t want to be sharing code with CCP sponsored backdoors.