←back to thread

466 points CoolCold | 1 comments | | HN request time: 0.206s | source
Show context
StimDeck ◴[] No.40207890[source]
Just a reminder that there are plenty of systemd-less distros available. Also a reminder that those distros would have been safe from the nearly-solar-winds-level backdooring of Linux distros from XZ utils.
replies(3): >>40208737 #>>40215800 #>>40217457 #
nialv7 ◴[] No.40215800[source]
Can you even hear what you are saying? Don't you find it ridiculous to blame the XZ backdoor on systemd, instead of the actual hacker?

Even if systemd did not exist, the hacker would have just picked something else to infiltrate.

replies(2): >>40216309 #>>40217355 #
1. bitwize ◴[] No.40216309[source]
Of course, the actual hacker was to blame, but systemd was implicated. The fact that the attacker was willing to settle for compromising just Debian and Red Hat systems indicated that they perceived the path from xz to libsystemd was the easiest way to effect the backdoor and that doing it any other way would have been too much work for marginally little gain (Red Hat and Debian systems being so common).