Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

It's weird now that "it's right there in the open",

Listed among the most recent commits there is "update two test files" https://git.tukaani.org/?p=xz.git;a=commitdiff;h=6e636819e8f...

And it's kind of smart to attack a compression library - you have plausible deniability for these opaque binary blobs - they are supposedly test cases, but in reality encode parts of the backdoor.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: