An xz library backdoor stayed in Debian and Fedora repos for a month
The alert didn't come from a security scanner or corporate notice. It came from an SSH connection taking half a second longer than usual. The person who spotted it was testing something else, pulled the thread, and found the unthinkable: a backdoor embedded in xz, the compression library working behind the scenes in much of the GNU/Linux ecosystem. The package with a gift inside was available in repositories for about a month. Debian and Red Hat/Fedora are among the affected distributions; Arch and its derivatives seem to have escaped.
What did the xz backdoor allow?
According to the analysis emerging, the malicious code would have enabled direct SSH access to the machine as administrator without the owner noticing anything and without the permissions system acting as a barrier. In short: no need to hunt for an exploit that twists system variables or chain known flaws to escalate privileges. The door was already open.
Tools like chkrootkit, rkhunter, or Aide exist precisely to catch these types of intrusions. And even with them, it's not easy to arrive in time. Some rushed to downplay the issue as a simple eval inserted into a library build script. The nuance is significant, but it's worth remembering what an eval opens up when the package ends up running on third-party servers. The entire defensive architecture of the operating system assumes that whoever maintains a dependency plays fair. When they don't, the wall collapses on its own.
Why were Debian and Red Hat affected while Arch wasn't?
Not all distributions took the bait. Arch and its derivatives seem to have avoided this specific version, while Debian and the Red Hat/Fedora family did incorporate the compromised package. When the dependency is common, the flaw travels in a chain and drags everything hanging off it with it.
This asymmetry immediately fueled the old rivalry between distros. For years, the number of Linux users on the desktop, around 4%, served as a shield: few users, few targets. The conclusion several people draw is the opposite. As that percentage rises, the system becomes more attractive and attacks stop being anecdotal.
Volunteer maintenance, the weakest link
Here lies the core of the matter. The backdoor wasn't slipped in by an anonymous attacker from outside: it entered through the door of trust granted to those maintaining other people's code. According to the account that has circulated, a false identity would have been gaining fruta in various projects until having the margin to push changes to the package. No one has a machine to detect intentions.
The heart of the debate is economic. Security review of critical dependencies rests largely on volunteers who already spend ten hours a day doing the same thing for work. Reviewing others' lines of code for free and rigorously isn't a hobby: it's a second job without a paycheck. The warning hovering over this is explicit: either incentivize this labor, or scares will arrive exponentially.
One month in repositories: patch arrives, distrust remains
It was fixed quickly once the focus was placed. The problem isn't the patch, it's the window. One month of exposure in repositories feeding servers and production equipment. And the uncomfortable question no one answers with total peace of mind: if this package carried a gift, how many others might carry something similar without anyone looking?
The comparison with Windows appears again and again, almost always poorly framed. That the other system accumulates holes doesn't make this one insignificant. The advantage claimed is different: open source can be audited and, once the problem is detected, the fix arrives in hours, not whenever the manufacturer feels like it.
Missing is what doesn't fit in any headline: the bill. OpenSSL, the library that encrypted half the internet for years, was sustained by two regular payers and about $5,000 a year. With that arithmetic, the xz backdoor isn't an accident. It's what happens when critical infrastructure is funded like a hobby.
Summary of a discussion on Burbuja.info - Foro de economía, actualidad y política., translated from Spanish and reviewed before publication.
Read the full discussion (149 replies).
Gravel, manhole covers, and sprinklers can easily topple motorcyclists. This article explores the legal paradox that protects motorcycles while banning unbelted car driving.