Post History
No. There is no known danger. The XZ backdoor was serious and very nearly became a catastrophe, but it was patched before release. A few things happened as a result of the XZ debacle, wherein: ...
#2: Post edited
No. There is no known danger. The XZ backdoor was serious and *very nearly* became a catastrophe, but it was patched before release. A number of developers went on a tear looking for other planted vulnerabilities when XZ was fixed.- I think you are asking about this *now* rather than two years ago because of the interest sparked by [a Veritasium documentary on YouTube](https://www.youtube.com/watch?v=aoag03mSuXQ). The documentary is actually quite good and has interviews with first-party sources.
- No. There is no known danger. The XZ backdoor was serious and *very nearly* became a catastrophe, but it was patched before release.
- A few things happened as a result of the XZ debacle, wherein:
- - 👍 A number of developers went on a tear looking for other planted vulnerabilities when XZ was fixed.
- - 👍 There was a heightened awareness of supply-chain vulnerabilities from "helpful" (and particularly from forceful) contributors.
- - 👎 There was a rash of accusations about various people who had been contributors or bug reporters being sock puppets for hackers.
- Software has bugs. Use software (on your computer or the cloud) according to your risk tolerance. Netflix makes their own decisions, and you can decide whether that's in line with your preferences. Bear in mind that really *old* software has had more time to be patched but may have exploits that are better-known!
- I think you are asking about this *now* rather than two years ago because of the interest sparked by [a Veritasium documentary on YouTube](https://www.youtube.com/watch?v=aoag03mSuXQ). The documentary is actually quite good and has interviews with first-party sources.
#1: Initial revision
No. There is no known danger. The XZ backdoor was serious and *very nearly* became a catastrophe, but it was patched before release. A number of developers went on a tear looking for other planted vulnerabilities when XZ was fixed. I think you are asking about this *now* rather than two years ago because of the interest sparked by [a Veritasium documentary on YouTube](https://www.youtube.com/watch?v=aoag03mSuXQ). The documentary is actually quite good and has interviews with first-party sources.
