How a single hack infected the world’s most important operating system. Sponsored by NordVPN - Get exclusive NordVPN deal here: https://NordVPN.com/veritasium It’s risk free with Nord’s 30 day money-b
Another software engineer here who lived through this as it was happening. This is an incredibly well-done and accurate documentary of what happened, bravo to the Veritasium team for getting so many of the little technical details right. Amazing that you were able to squeeze in so much of the important context and backstory there.
The only thing I'd add that wasn't said in the video was how the OpenSSH developers responded after the backdoor was discovered. Maybe you cut this out for time, since the video was already very long. But the only reason that xz was a dependency of ssh at all was due to a transitive dependency on libsystemd, and the only reason it used libsystemd was to report the ssh daemon's status back to the systemd daemon. The OpenSSH developers decided to remove that dependency and instead implement their own version of the systemd protocol communication protocol after Unix domain sockets without relying on the shared library. By eliminating those dependencies, that reduces the possible attack surface of any future exploits. They also carefully scrutinized all of the other ssh dependencies to decide if they really needed all of those and for what purposes. For secu
as a compiler engineer, i like how in depth you covered this. being able to explain the linker, GOT, audit hooks, valgrind, etc at this level without dumbing it down isincredible!
While we are talking about Nation State actors we should not forget that in 2013, reports revealed that the NSA paid RSA Security $10 million to use a flawed random number generator as the default in its products, effectively creating a "backdoor" for government surveillance.
From someone that has spent over 25 years in cybersecurity and over 5 years podcasting, I was absolutely floored by the effort that went into this video.
So ambitious - you’re going to explain open source software, Linux, public private key encryption, and how this XZ backdoor worked and played out in under 60 minutes? Incredible job folks.
As a software engineer, I have to say: this is a great explanation for non-technical people without oversimplifying the important details. Really well done
I feel so sorry for Lasse. It really makes you realise how much we depend on these maintainers. I hope his mental health has improved and he's doing okay
A volunteer created GNU, a volunteer created Linux, a volunteer created SSH, a volunteer created XZ, and a volunteer discovered the backdoor attempt (he was employed by Microsoft but not as a Linux security researcher). Companies tried to sue people to prevent software freedom, and a nation state tried to create this backdoor. I'm noticing a pattern here...
Software engineer here. When this happened it was really mindblowing that it never hit mainstream media. Ive never seen a security flaw have a higher criticality.
Get your exclusive NordVPN deal here nordvpn.com/veritasium and try it risk free with Nord’s 30 day money-back guarantee!
We use cookies, device fingerprinting and cross-device tracking to personalise content, serve targeted advertising, and analyse how you use our site across your devices. By clicking Accept all you consent to the use of these tracking technologies. Your data may be used to build a profile of your interests and show you personalised ads on other sites.
Privacy policy
Comments (20)
Daily Junction discussion mixed with clearly attributed comments from the original video provider.
Join in — free. Comments on Daily Junction are for members, so real names stay rare and bots stay out.
One field. We email you a 6-digit code — no password needed. Your comment is kept while you do it.
Under 13? You’ll need a parent’s OK first — it takes them one click.
The only thing I'd add that wasn't said in the video was how the OpenSSH developers responded after the backdoor was discovered. Maybe you cut this out for time, since the video was already very long. But the only reason that xz was a dependency of ssh at all was due to a transitive dependency on libsystemd, and the only reason it used libsystemd was to report the ssh daemon's status back to the systemd daemon. The OpenSSH developers decided to remove that dependency and instead implement their own version of the systemd protocol communication protocol after Unix domain sockets without relying on the shared library. By eliminating those dependencies, that reduces the possible attack surface of any future exploits. They also carefully scrutinized all of the other ssh dependencies to decide if they really needed all of those and for what purposes. For secu
So ambitious - you’re going to explain open source software, Linux, public private key encryption, and how this XZ backdoor worked and played out in under 60 minutes? Incredible job folks.
It was an xz-stential threat.
Edit: Use the American pronunciation of xz like the video does. Then it reads exzeestential.
Most horror stories do.
Edit: 25k likes? For real?
It’s protected by individuals who care enough to look twice.
That’s both comforting and unsettling.
1. An elite hacker group with multiple years of prep time and millions of dollars in funding from a nation-state
2. A random German guy seeing inefficiency