Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

> looks like there was a bit of a slip-up

Indeed that is a suspicious or at least untrustworthy way to deflect the seriousness of a malware infection that potentially affects all users of an OS distribution.



Either way, nobody should use this distro ever again. It should be forked from a known good commit under a new maintainer.


Nobody injected any malicious code into the repository. This is a website being hacked. As you certainly know, after reading TFA.


Nobody has yet identified any malicious code in the repository.

How do you prove that the person hacking the website is not an associate of (or the same as) the person running the website?

If this were proprietary software then the software would be expected to die. Since this is open source, there is the option for the original project to die and for a fork to rise form the ashes.


Has a single website security incident ever brought an end to any software project, proprietary or otherwise?


I've been using Open Source since before the term was coined, and no, that's not my expectation at all.




Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: