The backdoor itself was added to the tool by one of its two main developers, who had spent three years making real and useful contributions and the past two being one of the two official maintainers. There is still the chance the account was compromised, but if it was, it was an extremely cautious takeover: the malicious code was added to the software periodically over a long period of time, with plausible explanations given every time, and when the final backdoored version was complete, the same user headed over to the developer site for one popular version of Linux to ask that it use the updated version as soon as possible since it supposedly fixed critical bugs.
And it came so close to being public. The backdoored version was shipped in the beta versions of three different versions of Linux, and for two days, in the main release of one distribution, Kali Linux. When there, it allowed someone with the right private key to start a new encrypted connection and hijack the machine entirely.
So how was it spotted? A single Microsoft developer was annoyed that a system was running slowly. That’s it. The developer, Andres Freund, was trying to uncover why a system running a beta version of Debian, a Linux distribution, was lagging when making encrypted connections. That lag was all of half a second, for logins. That’s it: before, it took Freund 0.3s to login, and after, it took 0.8s. That annoyance was enough to cause him to break out the metaphorical spanner and pull his system apart to find the cause of the problem.
TechScape: How one man stopped a potentially massive cyber-attack – by accident | Technology | The Guardian
Happy World Autism Acceptance (not awareness) Day! Remember to NOT support Autism Speaks as the organization is harmful for Autistics, not helpful. Don’t light it up blue. Go with #redinstead for actually Autistics.
Me explaining things to myself vs explaining things to other people
First clip: Sokka is wearing his goofy ass getup (blue hat and extended monocle) and fiddling with his dragon pipe explaining why Kyoshi couldn't have murdered Chin the Great while looking at a painting of her waving to the people in a ceremony.
Sokka: If Kyoshi was at the ceremony at sunset, she couldn't have been in Chin committing the crime. She has an alibi!
Clip two: Aang in a pillory at the crime scene presenting the evidence and failing miserably to unimpressed townspeople.
Aang: *whispering* Oh, yeah! *to the crowd* You see, I have very large feet. Furthermore, your temple matches your statue. But... I was in a painting at sunset. So there you have it, I'm not guilty!
The autistic urge to identify and comment every song that isnt properly credited in a tiktok just in case someone wats to listen to the whole thing instead of like 15 seconds of it