Re: Linux needs a security audit

Pierre-Elliott Bécue <[email protected]>
Newsgroups gmane.linux.debian.user,gmane.linux.debian.devel.project,gmane.linux.debian.user.events-eu
Message-ID <[email protected]>
Hello,

Michael Paoli <[email protected]> wrote on 15/09/2025 at 01:20:23+0200:

> "extraordinary claims require extraordinary evidence".
> Please point to the evidence.
> Both Linux and Tor, OpenSource,
> and with source/version control and history, etc.
> So if they were compromised at any point, or even
> unintentional compromising bugs introduced, one should
> well be able to point that out, and when, and the responsible
> party that introduced such.
> While I'm sure there are entities that would wish to compromise
> Linux and/or Tor, actually doing so is quite non-trivial, given all the
> eyes on the code, various testing and monitoring, etc.  Even when a
> bad actor intentionally compromised xz, that was caught in relatively
> short order, and long before making it to any Debian stable release or the like.
> May want to first look at simpler more probable explanations before presuming
> the much less probable.  E.g. if you believe you were compromised, were you
> compromised via other simpler, easier means, e.g. somehow otherwise leaking
> your information/data - such as a compromised Tor entry relay, or many
> other possible
> means, which would be a much simpler and easier attack/compromise
> than what you claim.  There are many other possibilities,
> but that's just one that's far simpler and easier than what you're claiming.
>
> So, if you claim compromise of the code, point to the actual evidence,
> where exactly
> in the code is the compromise?  Otherwise you're making quite
> extraordinary claims,
> without the corresponding evidence to back those claims.
>
> And you're claiming both were compromised?  Really.  Sounds like
> conspiracy fodder without backing evidence.

I see these kind of mails as wasteful in terms of resources, I'd suggest
not to engage.

Bests,
-- 
PEB
signature.asc (application/pgp-signature, 853 B)
-----BEGIN PGP SIGNATURE-----

iQJDBAEBCgAtFiEE5CQeth7uIW7ehIz87iFbn7jEWwsFAmjIFT0PHHBlYkBkZWJp
YW4ub3JnAAoJEO4hW5+4xFsLz0kP/1wCShnTHTcz6flcr5NfaVOeYQTV28CNaiZF
QpOEt/yT2rOkh9IrOEtsyjyP7sG8EQoZznfwE26o3txKK+/cPu0039HlDDjRH24j
VxuoQLR7mqjYNmn1FVDVcMcGwz9sAsnlvF+e7Kg4YAHSr+MxZxGvxtY1pDA+BeL6
SY0E2Nk/UfCwDGJjOx4U3KJnhJsUt8EjbdhrjPgs8YBQYe80yACTPguW83IkvGIt
xLMsrQU/MhnR3J/Lvw/RNx+i/pqixkXHBW2IABZ9A4rBqBInVf/G+7L6FtIaVMLm
eqq3i3k5RrcWOUS1qfI/Isx/iz1qFY9HaH0uZ4q0LGbzLUnjbyjwcCT0fDL34OmH
dJgbWReI+ScWshK76bcWfnX9D4FCFJJJqgg4+f4HQjQRtPpW/HThmNmxDw14m3hC
f0Lhx6RaqE8AHzgOPil6qnml6CTYqfcOWJKOzdRYJow5TGbLBmvv/aogWAQ+FUHB
+CSA625MnE+MtKpnHoGVIiWldoq3bxa9QDGuCs0rQtEBp5+FwEdjfeVF+C9KazyV
PUubivTYVy0aMPp7WzGiwoZrsknzpIQtW7ABW62twY5s2H5W8rAVQ3/Jku+brE9F
ASm2lgBfyFh3rQANNMh48cyAkQid/B2S5Hb16x6WNpG53RrmWIfHn1NqaUESWz/C
nWD9O+RB
=/+tu
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.