Episode

The XZ exploit: The day the internet got lucky

Podcast
Technology Pill
Published
Jul 27, 2024
Duration seconds
3295
Processing state
not_requested
Canonical source
https://podcasters.spotify.com/pod/show/technology-pill/episodes/The-XZ-exploit-The-day-the-internet-got-lucky-e2mg2th
Audio
https://anchor.fm/s/152674c8/podcast/play/89704817/https%3A%2F%2Fd3ctxlq1ktw2nl.cloudfront.net%2Fstaging%2F2024-6-26%2F383873124-44100-2-4be2c282c596e.m4a
JSON
/v1/public/podcasts/technology-pill-560921/episodes/the-xz-exploit-the-day-the-internet-got-lucky
Markdown
/podcast/technology-pill-560921/the-xz-exploit-the-day-the-internet-got-lucky.md

Actions

  • POST https://stenobird.com/v1/public/podcasts/technology-pill-560921/episodes/the-xz-exploit-the-day-the-internet-got-lucky/transcription-requests
    Idempotently request low-priority transcript generation for this episode.
  • GET https://stenobird.com/podcast/technology-pill-560921/the-xz-exploit-the-day-the-internet-got-lucky.md
    Read the agent-friendly Markdown representation of this episode resource.

Summary

This week we're talking about a backdoor inserted into a popular Linux file compression tool, which had the potential to massively undermine the security of vast swathes of the internet. What happened? How did it happen? And how was it thwarted? Links - Andres Freund's Mastodon - where he revealed the backdoor: https://mastodon.social/@AndresFreundTec - Read more in Ars Technica's article about it: https://arstechnica.com/security/2024/03/backdoor-found-in-widely-used-linux-utility-breaks-encrypted-ssh-connections/ - Read more in the verge's article about it https://www.theverge.com/2024/4/2/24119342/xz-utils-linux-backdoor-attempt - Read more in Wired's article about it https://www.wired.com/story/jia-tan-xz-backdoor/ - Check out this excellent and very helpful diagram: https://twitter.com/fr0gger_/status/1775759514249445565 - The XKCD comic we mention: https://xkcd.com/538/