ブックマーク / www.schneier.com (1)

  • Backdoor in XZ Utils That Almost Happened - Schneier on Security

    Last week, the Internet dodged a major nation-state attack that would have had catastrophic cybersecurity repercussions worldwide. It’s a catastrophe that didn’t happen, so it won’t get much attention—but it should. There’s an important moral to the story of the attack and its discovery: The security of the global Internet depends on countless obscure pieces of software written and maintained by e

    wkatu
    wkatu 2024/04/13
    ブルース・シュナイアー"The fundamental problem is that tech companies dislike spending extra money even more than programmers dislike doing extra work." "The big tech companies pledged $30 million in funding after the critical Log4j supply chain vulnerability, but they never delivered."
  • 1