We are now at t+26h. Please compare how much we knew about the xz-attack after less than a day with what we know about the chain of events of giant outage yesterday.

If something similar had been caused by an OSS component, we would see congress discussing a ban on open software in critical infrastructure already.

  • HubertManne@moist.catsweat.com
    link
    fedilink
    arrow-up
    14
    ·
    5 months ago

    Solar winds was a pretty big deal and I would say bigger than the current thing. Although that just strengthens your argument given orion was not open source and they were hacked and the malevolent code was injected into their system essentially internally and had been tested for a bit by the hackers which if their code had been viewable might have allowed it to be caught before becoming such a big deal.