• 0 Posts
  • 7 Comments
Joined 1 year ago
cake
Cake day: August 15th, 2023

help-circle

  • I’m going to be honest, I’m getting a little tired of hearing everyone’s thoughts on the xz backdoor. It’s discouraging and sucks when every detail of the project which, keep in mind, was maintained by one person who fell victim to a social engineering attack, is scrutinized. It makes me concerned about anyone depending on any of my projects.

    Especially the comments on things such as the build scripts, which this kind of article seems to gravitate towards. If the build scripts were tiny and checked then the attack vector would have just been different, I’m not even too sure the language mattered. The attack was social engineering, after that it was pretty much project agnostic. xz was targeted cause the maintainer was done working on it and it was heavily depended on.



  • Metype @lemmy.worldtoProgrammer Humor@lemmy.mlSTOP WRITING C
    link
    fedilink
    English
    arrow-up
    1
    ·
    10 months ago

    There’s a project I could have written in Rust. Maybe some of the headache wouldn’t have ever happened using Rust.

    I also didn’t know Rust at the time and it was a large project with unkind deadlines. I think the right tool for the job can also depend on available resources. So while the more unsafe, older tool I used caused a few small issues that Rust would not have; the project wouldn’t have been finished if I’d used Rust.