Re: Linux needs a security audit
Pierre-Elliott Bécue <[email protected]> Mon, 15 Sep 2025 15:31:41 +0200
| Newsgroups | gmane.linux.debian.user,gmane.linux.debian.devel.project,gmane.linux.debian.user.events-eu |
|---|---|
| Message-ID | <[email protected]> |
--=-=-= Content-Type: text/plain Content-Transfer-Encoding: quoted-printable Hello, Michael Paoli <[email protected]> wrote on 15/09/2025 at 01:20:23+= 0200: > "extraordinary claims require extraordinary evidence". > Please point to the evidence. > Both Linux and Tor, OpenSource, > and with source/version control and history, etc. > So if they were compromised at any point, or even > unintentional compromising bugs introduced, one should > well be able to point that out, and when, and the responsible > party that introduced such. > While I'm sure there are entities that would wish to compromise > Linux and/or Tor, actually doing so is quite non-trivial, given all the > eyes on the code, various testing and monitoring, etc. Even when a > bad actor intentionally compromised xz, that was caught in relatively > short order, and long before making it to any Debian stable release or th= e like. > May want to first look at simpler more probable explanations before presu= ming > the much less probable. E.g. if you believe you were compromised, were y= ou > compromised via other simpler, easier means, e.g. somehow otherwise leaki= ng > your information/data - such as a compromised Tor entry relay, or many > other possible > means, which would be a much simpler and easier attack/compromise > than what you claim. There are many other possibilities, > but that's just one that's far simpler and easier than what you're claimi= ng. > > So, if you claim compromise of the code, point to the actual evidence, > where exactly > in the code is the compromise? Otherwise you're making quite > extraordinary claims, > without the corresponding evidence to back those claims. > > And you're claiming both were compromised? Really. Sounds like > conspiracy fodder without backing evidence. I see these kind of mails as wasteful in terms of resources, I'd suggest not to engage. Bests, =2D-=20 PEB --=-=-= Content-Type: application/pgp-signature; name="signature.asc" -----BEGIN PGP SIGNATURE----- iQJDBAEBCgAtFiEE5CQeth7uIW7ehIz87iFbn7jEWwsFAmjIFT0PHHBlYkBkZWJp YW4ub3JnAAoJEO4hW5+4xFsLz0kP/1wCShnTHTcz6flcr5NfaVOeYQTV28CNaiZF QpOEt/yT2rOkh9IrOEtsyjyP7sG8EQoZznfwE26o3txKK+/cPu0039HlDDjRH24j VxuoQLR7mqjYNmn1FVDVcMcGwz9sAsnlvF+e7Kg4YAHSr+MxZxGvxtY1pDA+BeL6 SY0E2Nk/UfCwDGJjOx4U3KJnhJsUt8EjbdhrjPgs8YBQYe80yACTPguW83IkvGIt xLMsrQU/MhnR3J/Lvw/RNx+i/pqixkXHBW2IABZ9A4rBqBInVf/G+7L6FtIaVMLm eqq3i3k5RrcWOUS1qfI/Isx/iz1qFY9HaH0uZ4q0LGbzLUnjbyjwcCT0fDL34OmH dJgbWReI+ScWshK76bcWfnX9D4FCFJJJqgg4+f4HQjQRtPpW/HThmNmxDw14m3hC f0Lhx6RaqE8AHzgOPil6qnml6CTYqfcOWJKOzdRYJow5TGbLBmvv/aogWAQ+FUHB +CSA625MnE+MtKpnHoGVIiWldoq3bxa9QDGuCs0rQtEBp5+FwEdjfeVF+C9KazyV PUubivTYVy0aMPp7WzGiwoZrsknzpIQtW7ABW62twY5s2H5W8rAVQ3/Jku+brE9F ASm2lgBfyFh3rQANNMh48cyAkQid/B2S5Hb16x6WNpG53RrmWIfHn1NqaUESWz/C nWD9O+RB =/+tu -----END PGP SIGNATURE----- --=-=-=--