profile-img
Ian Coldwater 📦💥

@IanColdwater

Kubernetes SIG Security co-chair, container escape artist, goose in the mainframe. They/them. Legacy verified. Stay punk 🏴

calendar_today20-03-2016 01:42:51

122,5K Tweets

106,4K Followers

1,1K Following

Ian Coldwater 📦💥(@IanColdwater) 's Twitter Profile Photo

This upstream supply chain security attack is the kind of nightmare scenario that has gotten people describing it called hysterical for years.

It’s real. Sleep well.

backdoor in upstream xz/liblzma leading to ssh server compromise

openwall.com/lists/oss-secu…

account_circle
Ian Coldwater 📦💥(@IanColdwater) 's Twitter Profile Photo

The obfuscated backdoor was found by someone who noticed and looked into performance degradation, basically out of sheer luck. We’re all lucky it got caught at all, and as soon as it did. It would have been much worse if it had kept on for longer

mastodon.social/@AndresFreundT…

account_circle