Oxide and Friends

Discovering the XZ Backdoor with Andres Freund


Listen Later

Andres Freund joined Bryan and Adam to talk about his discovery of the xz backdoor. It’s an incredible story… so great to get into the details with Andres. We started by ranting about the coverage in the New York Times… coverage that explicitly refused to dig into the details! It’s all the more shocking because the big story here is how Andres’ penchant for digging into the details is what saved us all from what would have been a pervasive and damaging attack!

In addition to Bryan Cantrill and Adam Leventhal, we were joined by special guest Andres Freund.

Our research for this episode:

  • Andres' initial public disclosure
  • New York Times: Did One Guy Just Stop a Huge Cyberattack? by Kevin Roose
  • Kevin Roose
  • New York Times front page from April 4th, 2024
  • How I got started as a developer with Andres Freund & Heikki Linnakangas | Path To Citus Con Ep08
  • The Mystery of ‘Jia Tan,’ the XZ Backdoor Mastermind | WIRED
  • How one volunteer stopped a backdoor from exposing Linux systems worldwide - The Verge
  • Linux backdoor was a long con, possibly with nation-state support, experts say - Nextgov/FCW
  • research!rsc: Timeline of the xz open source attack
  • Brian Krebs thread on mastodon
  • Xz/liblzma: Bash-stage Obfuscation Explained
  • A Microcosm of the interactions in Open Source projects
  • Risky Business #743 -- A chat about the xz backdoor with the guy who found it (podcast)
  • Risky Biz News: F-Droid narrowly avoided XZ-like incident in 2020 (podcast)
  • What we know about the xz Utils backdoor that almost infected the world | Ars Technica
  • Everything I know about the XZ backdoor
  • LINUX Unplugged 556: The xz Backdoor Exposed 🚨 (podcast)

If we got something wrong or missed something, please file a PR! Our next show will likely be on Monday at 5p Pacific Time on our Discord server; stay tuned to our Mastodon feeds for details, or subscribe to this calendar. We'd love to have you join us, as we always love to hear from new speakers!

Recorded April 8th, 2024

...more
View all episodesView all episodes
Download on the App Store

Oxide and FriendsBy Oxide Computer Company

  • 4.9
  • 4.9
  • 4.9
  • 4.9
  • 4.9

4.9

46 ratings


More shows like Oxide and Friends

View all
Software Engineering Radio - the podcast for professional software developers by se-radio@computer.org

Software Engineering Radio - the podcast for professional software developers

262 Listeners

The Changelog: Software Development, Open Source by Changelog Media

The Changelog: Software Development, Open Source

285 Listeners

Talk Python To Me by Michael Kennedy

Talk Python To Me

585 Listeners

Software Engineering Daily by Software Engineering Daily

Software Engineering Daily

631 Listeners

Soft Skills Engineering by Jamison Dance and Dave Smith

Soft Skills Engineering

271 Listeners

Python Bytes by Michael Kennedy and Brian Okken

Python Bytes

213 Listeners

Syntax - Tasty Web Development Treats by Wes Bos & Scott Tolinski - Full Stack JavaScript Web Developers

Syntax - Tasty Web Development Treats

985 Listeners

CoRecursive: Coding Stories by Adam Gordon Bell - Software Developer

CoRecursive: Coding Stories

185 Listeners

Kubernetes Podcast from Google by Abdel Sghiouar, Kaslin Fields

Kubernetes Podcast from Google

183 Listeners

The Stack Overflow Podcast by The Stack Overflow Podcast

The Stack Overflow Podcast

63 Listeners

Dwarkesh Podcast by Dwarkesh Patel

Dwarkesh Podcast

319 Listeners

Latent Space: The AI Engineer Podcast by swyx + Alessio

Latent Space: The AI Engineer Podcast

64 Listeners

Rust in Production by Matthias Endler

Rust in Production

11 Listeners

Complex Systems with Patrick McKenzie (patio11) by Patrick McKenzie

Complex Systems with Patrick McKenzie (patio11)

101 Listeners

The Pragmatic Engineer by Gergely Orosz

The Pragmatic Engineer

48 Listeners