what i've read about this backdoor issue so far i find puzzling, as well as a little frightening. seems with enough resources any big actor, state or otherwise, is and will be able to get around opensource security, eventually.
Technologist vs spy: the xz backdoor debateWell — we just witnessed one of the most daring infosec capers of my career. Here’s what we know so far: some time ago, an unknown party evidently noticed that liblzma (aka xz) — a relatively obscure open-source compression library — was a dependency of