{"id":4880,"date":"2024-04-09T08:46:22","date_gmt":"2024-04-09T06:46:22","guid":{"rendered":"https:\/\/rock-the-prototype.com\/unkategorisiert\/invisible-attacker-via-xz-backdoor-it-security-software-integrity\/"},"modified":"2024-04-09T09:53:16","modified_gmt":"2024-04-09T07:53:16","slug":"invisible-attacker-via-xz-backdoor-it-security-software-integrity","status":"publish","type":"post","link":"https:\/\/rock-the-prototype.com\/en\/it-security\/invisible-attacker-via-xz-backdoor-it-security-software-integrity\/","title":{"rendered":"Invisible attacker via xz backdoor &#8211; IT Security &amp; Software Integrity"},"content":{"rendered":"<p><\/p><div class=\"fusion-fullwidth fullwidth-box fusion-builder-row-1 fusion-flex-container nonhundred-percent-fullwidth non-hundred-percent-height-scrolling\" style=\"--awb-border-radius-top-left:0px;--awb-border-radius-top-right:0px;--awb-border-radius-bottom-right:0px;--awb-border-radius-bottom-left:0px;--awb-flex-wrap:wrap;\"><div class=\"fusion-builder-row fusion-row fusion-flex-align-items-flex-start fusion-flex-content-wrap\" style=\"max-width:1144px;margin-left: calc(-4% \/ 2 );margin-right: calc(-4% \/ 2 );\"><div class=\"fusion-layout-column fusion_builder_column fusion-builder-column-0 fusion_builder_column_1_1 1_1 fusion-flex-column\" style=\"--awb-bg-size:cover;--awb-width-large:100%;--awb-margin-top-large:0px;--awb-spacing-right-large:1.92%;--awb-margin-bottom-large:0px;--awb-spacing-left-large:1.92%;--awb-width-medium:100%;--awb-spacing-right-medium:1.92%;--awb-spacing-left-medium:1.92%;--awb-width-small:100%;--awb-spacing-right-small:1.92%;--awb-spacing-left-small:1.92%;\"><div class=\"fusion-column-wrapper fusion-flex-justify-content-flex-start fusion-content-layout-column\"><div class=\"fusion-text fusion-text-1\"><div id=\"ez-toc-container\" class=\"ez-toc-v2_0_86 counter-hierarchy ez-toc-counter ez-toc-custom ez-toc-container-direction\">\n<div class=\"ez-toc-title-container\">\n<p class=\"ez-toc-title\" style=\"cursor:inherit\">Inhaltsverzeichnis<\/p>\n<span class=\"ez-toc-title-toggle\"><a href=\"#\" class=\"ez-toc-pull-right ez-toc-btn ez-toc-btn-xs ez-toc-btn-default ez-toc-toggle\" aria-label=\"Toggle Table of Content\"><span class=\"ez-toc-js-icon-con\"><span class=\"\"><span class=\"eztoc-hide\" style=\"display:none;\">Toggle<\/span><span class=\"ez-toc-icon-toggle-span\"><svg style=\"fill: #ffffff;color:#ffffff\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" class=\"list-377408\" width=\"20px\" height=\"20px\" viewBox=\"0 0 24 24\" fill=\"none\"><path d=\"M6 6H4v2h2V6zm14 0H8v2h12V6zM4 11h2v2H4v-2zm16 0H8v2h12v-2zM4 16h2v2H4v-2zm16 0H8v2h12v-2z\" fill=\"currentColor\"><\/path><\/svg><svg style=\"fill: #ffffff;color:#ffffff\" class=\"arrow-unsorted-368013\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" width=\"10px\" height=\"10px\" viewBox=\"0 0 24 24\" version=\"1.2\" baseProfile=\"tiny\"><path d=\"M18.2 9.3l-6.2-6.3-6.2 6.3c-.2.2-.3.4-.3.7s.1.5.3.7c.2.2.4.3.7.3h11c.3 0 .5-.1.7-.3.2-.2.3-.5.3-.7s-.1-.5-.3-.7zM5.8 14.7l6.2 6.3 6.2-6.3c.2-.2.3-.5.3-.7s-.1-.5-.3-.7c-.2-.2-.4-.3-.7-.3h-11c-.3 0-.5.1-.7.3-.2.2-.3.5-.3.7s.1.5.3.7z\"\/><\/svg><\/span><\/span><\/span><\/a><\/span><\/div>\n<nav><ul class='ez-toc-list ez-toc-list-level-1 ' ><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-1\" href=\"https:\/\/rock-the-prototype.com\/en\/it-security\/invisible-attacker-via-xz-backdoor-it-security-software-integrity\/#Why_software_integrity_is_our_invisible_shield_against_cyberattacks\" >Why software integrity is our invisible shield against cyberattacks<\/a><ul class='ez-toc-list-level-3' ><li class='ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-2\" href=\"https:\/\/rock-the-prototype.com\/en\/it-security\/invisible-attacker-via-xz-backdoor-it-security-software-integrity\/#The_backdoor_hidden_in_Linux_distributions_%E2%80%93_What_happened\" >The backdoor hidden in Linux distributions &#8211; What happened?<\/a><\/li><\/ul><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-3\" href=\"https:\/\/rock-the-prototype.com\/en\/it-security\/invisible-attacker-via-xz-backdoor-it-security-software-integrity\/#What_is_it_about_in_detail_All_the_facts_at_a_glance\" >What is it about in detail? All the facts at a glance!<\/a><ul class='ez-toc-list-level-3' ><li class='ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-4\" href=\"https:\/\/rock-the-prototype.com\/en\/it-security\/invisible-attacker-via-xz-backdoor-it-security-software-integrity\/#Facts_of_the_case\" >Facts of the case<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-5\" href=\"https:\/\/rock-the-prototype.com\/en\/it-security\/invisible-attacker-via-xz-backdoor-it-security-software-integrity\/#Evaluation\" >Evaluation<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-6\" href=\"https:\/\/rock-the-prototype.com\/en\/it-security\/invisible-attacker-via-xz-backdoor-it-security-software-integrity\/#Measures\" >Measures<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-7\" href=\"https:\/\/rock-the-prototype.com\/en\/it-security\/invisible-attacker-via-xz-backdoor-it-security-software-integrity\/#Additional_information\" >Additional information<\/a><\/li><\/ul><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-8\" href=\"https:\/\/rock-the-prototype.com\/en\/it-security\/invisible-attacker-via-xz-backdoor-it-security-software-integrity\/#Why_is_the_focus_here_on_the_integrity_of_software\" >Why is the focus here on the integrity of software?<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-9\" href=\"https:\/\/rock-the-prototype.com\/en\/it-security\/invisible-attacker-via-xz-backdoor-it-security-software-integrity\/#What_is_software_integrity\" >What is software integrity?<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-10\" href=\"https:\/\/rock-the-prototype.com\/en\/it-security\/invisible-attacker-via-xz-backdoor-it-security-software-integrity\/#Cryptoagility\" >Cryptoagility<\/a><ul class='ez-toc-list-level-3' ><li class='ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-11\" href=\"https:\/\/rock-the-prototype.com\/en\/it-security\/invisible-attacker-via-xz-backdoor-it-security-software-integrity\/#Agile_security_strategies_instead_of_static_security_models\" >Agile security strategies instead of static security models<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-12\" href=\"https:\/\/rock-the-prototype.com\/en\/it-security\/invisible-attacker-via-xz-backdoor-it-security-software-integrity\/#Valuable_insights_that_we_can_take_away_with_us_and_implement_directly\" >Valuable insights that we can take away with us and implement directly:<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-13\" href=\"https:\/\/rock-the-prototype.com\/en\/it-security\/invisible-attacker-via-xz-backdoor-it-security-software-integrity\/#Open_source_myth_debunked_Why_transparency_in_the_software_world_automatically_means_security\" >Open source myth debunked: Why transparency in the software world automatically means security<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-14\" href=\"https:\/\/rock-the-prototype.com\/en\/it-security\/invisible-attacker-via-xz-backdoor-it-security-software-integrity\/#Transparency_promotes_security\" >Transparency promotes security<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-15\" href=\"https:\/\/rock-the-prototype.com\/en\/it-security\/invisible-attacker-via-xz-backdoor-it-security-software-integrity\/#Joint_effort\" >Joint effort<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-16\" href=\"https:\/\/rock-the-prototype.com\/en\/it-security\/invisible-attacker-via-xz-backdoor-it-security-software-integrity\/#Safety_audits_and_reviews\" >Safety audits and reviews<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-17\" href=\"https:\/\/rock-the-prototype.com\/en\/it-security\/invisible-attacker-via-xz-backdoor-it-security-software-integrity\/#False_equation_of_availability_and_vulnerability\" >False equation of availability and vulnerability<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-18\" href=\"https:\/\/rock-the-prototype.com\/en\/it-security\/invisible-attacker-via-xz-backdoor-it-security-software-integrity\/#Use_in_safety-critical_systems\" >Use in safety-critical systems<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-19\" href=\"https:\/\/rock-the-prototype.com\/en\/it-security\/invisible-attacker-via-xz-backdoor-it-security-software-integrity\/#Example_of_successful_OSS_security_models\" >Example of successful OSS security models<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-20\" href=\"https:\/\/rock-the-prototype.com\/en\/it-security\/invisible-attacker-via-xz-backdoor-it-security-software-integrity\/#Your_click_our_common_path_How_your_support_shapes_our_digital_future\" >Your click, our common path: How your support shapes our digital future<\/a><\/li><\/ul><\/li><\/ul><\/nav><\/div>\n<h2 class=\"entry-title fusion-post-title fusion-responsive-typography-calculated\" data-fontsize=\"38\" data-lineheight=\"57px\"><span class=\"ez-toc-section\" id=\"Why_software_integrity_is_our_invisible_shield_against_cyberattacks\"><\/span>Why software integrity is our invisible shield against cyberattacks<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p id=\"ember317\" class=\"ember-view\">How robust software development practices and effective IT security monitoring protect us from the well-hidden dangers of the cyber world.<\/p>\n<p id=\"ember318\" class=\"ember-view reader-content-blocks__paragraph\">Now that cyberattacks are becoming increasingly dangerous and regular and digital borders are becoming increasingly invisible, <strong>software integrity <\/strong>is taking on a whole new significance as a fundamental pillar of our cybersecurity.<\/p>\n<p id=\"ember319\" class=\"ember-view reader-content-blocks__paragraph\">This can never be shown more clearly than in the current <strong>xz backdoor<\/strong> incident. The invisible attackers not only expose the vulnerability of our digital infrastructures, but also bring an urgent question into focus:<\/p>\n<blockquote>\n<p>&ldquo;How can we effectively protect ourselves against the shadow work of cyber criminals?&rdquo;<\/p>\n<\/blockquote>\n\n<\/div><div class=\"fusion-text fusion-text-2\"><p id=\"ember321\" class=\"ember-view reader-content-blocks__paragraph\">In this article, I shed light on the background to the latest cyberattack and the critical role of software integrity as our invisible protective shield.<\/p>\n<p id=\"ember322\" class=\"ember-view reader-content-blocks__paragraph\">In doing so, I will highlight constructive IT security measures that each of us can take to strengthen the digital fortresses that protect our data, our privacy and our security.<\/p>\n<p id=\"ember323\" class=\"ember-view reader-content-blocks__paragraph\">Join me on a journey through the complex waters of IT security, which is more than just a battle against code &ndash; it&rsquo;s a constant struggle for trust in an increasingly connected world.<\/p>\n<h3 id=\"ember324\" class=\"ember-view\">The backdoor hidden in Linux distributions &ndash; What happened?<\/h3>\n<p id=\"ember325\" class=\"ember-view reader-content-blocks__paragraph\">On March 29, 2024, the open source provider Red Hat reveals a disturbing discovery: <strong>Malicious code has been identified<\/strong>in <strong>versions 5.6.0<\/strong> and <strong>5.6.1<\/strong> of the widely used <strong>&lsquo;xz&rsquo; tools<\/strong> and <strong>software libraries<\/strong>!<\/p>\n<p id=\"ember326\" class=\"ember-view reader-content-blocks__paragraph\">This malicious code enables attackers to bypass the <strong><a href=\"https:\/\/rock-the-prototype.com\/en\/it-security\/authentication\/\" target=\"_blank\" title=\"Authentication is a multi-step process in identity management. Authentication in an IT system implements IT security functions that are realized by various security services and components.\" class=\"encyclopedia\">authentication<\/a> systems via systemd<\/strong> and gain <strong>unauthorized access<\/strong>. <strong>Fedora versions 41<\/strong> and <strong>Fedora Rawhide<\/strong> were specifically affected, although the potential threat goes far beyond these software releases.<\/p>\n<\/div><div class=\"fusion-text fusion-text-3\"><p id=\"ember327\" class=\"ember-view reader-content-blocks__paragraph\">The <strong>vulnerability<\/strong>, published under the designation <a href=\"https:\/\/www.bsi.bund.de\/SharedDocs\/Cybersicherheitswarnungen\/DE\/2024\/2024-223608-1032.html\" target=\"_blank\" rel=\"noopener\"><br>\n  <strong>CVE-2024-3094<\/strong><br>\n<\/a>received the highest possible <strong>CVSS score<\/strong> of <strong>10\/10<\/strong> and was therefore classified as <strong>critical <\/strong>. Their discovery highlights the latent <strong>risks in the software supply chain<\/strong> and the need to recognize <strong>software integrity as a central element of cybersecurity strategy<\/strong>.<\/p>\n<p id=\"ember328\" class=\"ember-view reader-content-blocks__paragraph\">Despite specifically affecting Fedora 41 and Fedora Rawhide at Red Hat, the incident signaled a wide-ranging risk, as &lsquo;xz&rsquo; tools are used in numerous Linux distributions due to their efficiency and compatibility. The attack highlighted not only the sophistication of modern cyber threats, but also the critical importance of vigilance and ongoing testing of software products, even if they come from trusted sources.<\/p>\n<p id=\"ember329\" class=\"ember-view reader-content-blocks__paragraph\">In response to the discovery, immediate action was taken to address the vulnerability and update the affected software. At the same time, the community and security experts initiated a broad-based investigation to understand the extent of the compromise and develop future prevention strategies. This incident serves as a stern reminder of the constant threat of <a href=\"https:\/\/rock-the-prototype.com\/en\/it-security\/cybercrime\/\" target=\"_blank\" title=\"What is cybercrime? Cybercrime refers to illegal activities that are carried out using the internet or other forms of digital communication. This includes a variety of cybercrimes such as cyber fraud, cyber theft of digital identities, the spread of malware, unauthorized access to data and systems, and attacks on network infrastructures. Cybercrime uses digital technologies as a means to an end. Find out more now!\" class=\"encyclopedia\">cybercrime<\/a> and the vital role that software integrity plays in the fight against unseen attackers.<\/p>\n<h2 id=\"ember330\" class=\"ember-view\"><span class=\"ez-toc-section\" id=\"What_is_it_about_in_detail_All_the_facts_at_a_glance\"><\/span>What is it about in detail? All the facts at a glance!<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p id=\"ember331\" class=\"ember-view reader-content-blocks__paragraph\">Here you can find all the facts at a glance:<\/p>\n<h3 id=\"ember332\" class=\"ember-view\"><span class=\"ez-toc-section\" id=\"Facts_of_the_case\"><\/span>Facts of the case<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<ul>\n<li><strong>Date of the announcement:<\/strong> 29.03.2024<\/li>\n<li><strong>Affected software:<\/strong> &ldquo;xz&rdquo; tools and libraries<\/li>\n<li><strong>Versions:<\/strong> 5.6.0 and 5.6.1<\/li>\n<li><strong>Schwachstellen-ID:<\/strong> CVE-2024-3094<\/li>\n<li><strong>Affected distributions:<\/strong> Specifically Fedora 41 and Fedora Rawhide; other distributions may also be affected.<\/li>\n<li><strong>Distributions not affected:<\/strong> Amazon Linux, Red Hat Enterprise Linux (RHEL), SUSE Linux Enterprise Server, SUSE Linux Enterprise Server Micro, Ubuntu<\/li>\n<li><strong>Vulnerability assessment:<\/strong> Critical (CVSS score 10\/10)<\/li>\n<\/ul>\n<h3 id=\"ember334\" class=\"ember-view\"><span class=\"ez-toc-section\" id=\"Evaluation\"><\/span>Evaluation<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<ul>\n<li><strong>Description<\/strong>: Malicious code within the affected &ldquo;xz&rdquo; versions allows to bypass authentication via systemd in sshd.<\/li>\n<li><strong>Distribution and use:<\/strong> &ldquo;xz&rdquo; is used in almost every Linux distribution, both in community projects and in commercial products, which implies a widespread impact of the vulnerability.<\/li>\n<li><strong>Exploitation risk:<\/strong> Details on exploitation and proof-of-concepts were not known at the time of publication. Utilization is subject to certain conditions that have not yet been fully disclosed.<\/li>\n<\/ul>\n<h3 id=\"ember336\" class=\"ember-view\"><span class=\"ez-toc-section\" id=\"Measures\"><\/span>Measures<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<ul>\n<li><strong>Recommended steps:<\/strong> Check and adapt according to the recommendations of the manufacturers of the respective Linux distributions. This can include downgrading to secure &ldquo;xz&rdquo; versions or shutting down affected systems.<\/li>\n<li><strong>Specific instructions for distributions:<\/strong> Includes downgrade instructions for openSUSE and instructions for users of distributions such as Alpine, Arch, Debian, Fedora, Gentoo, Kali, and openSUSE, among others.<\/li>\n<li><strong>Tools for checking:<\/strong> Publication of tools and instructions for checking your own IT systems for the vulnerability.<\/li>\n<\/ul>\n<h3 id=\"ember338\" class=\"ember-view\"><span class=\"ez-toc-section\" id=\"Additional_information\"><\/span>Additional information<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<ul>\n<li><strong>Traffic Light Protocol (TLP):<\/strong> TLP:CLEAR, which allows unlimited forwarding of information.<\/li>\n<li><strong>Important links:<\/strong> Links to security warnings, vulnerability assessment tools and discussions on the backdoor issue.<\/li>\n<\/ul>\n<h2 id=\"ember340\" class=\"ember-view\"><span class=\"ez-toc-section\" id=\"Why_is_the_focus_here_on_the_integrity_of_software\"><\/span>Why is the focus here on the integrity of software?<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p id=\"ember341\" class=\"ember-view reader-content-blocks__paragraph\">When dealing with the<strong> critical backdoor <\/strong>in the &ldquo;xz&rdquo; tools and software libraries, both <strong>cryptoagility<\/strong> and <strong>software integrity<\/strong> are at the center of our interest if we are serious about <strong>robust software<\/strong> and <strong>effective IT security<\/strong>.<\/p>\n<p id=\"ember342\" class=\"ember-view reader-content-blocks__paragraph\">Each of these two aspects plays an important role in the context of cybersecurity, especially in responding to security incidents such as this one.<\/p>\n<h2 id=\"ember343\" class=\"ember-view\"><span class=\"ez-toc-section\" id=\"What_is_software_integrity\"><\/span>What is software integrity?<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p id=\"ember344\" class=\"ember-view reader-content-blocks__paragraph\">The <strong>integrity of software <\/strong>refers to ensuring that software is free from unauthorized modifications, whether through malicious interference or unintentional changes.<\/p>\n<p id=\"ember345\" class=\"ember-view reader-content-blocks__paragraph\">In the context of this incident, where a backdoor was found in widely used software, the integrity of software is of utmost importance. The malicious code allowed attackers to bypass authentication via <em>systemd<\/em> in <em>sshd<\/em>, which has a direct impact on the trustworthiness and security of the affected systems.<\/p>\n<p id=\"ember346\" class=\"ember-view reader-content-blocks__paragraph\">The <strong>prevention of<\/strong> such incidents and the ability to mitigate their impact are heavily dependent on <strong>robust mechanisms to ensure software integrity<\/strong>, including<strong> secure software development lifecycles<\/strong>, <strong>regular security audits<\/strong> and the use of<strong> digital signatures <\/strong>to verify the<strong> authenticity of software packages<\/strong>.<\/p>\n<h2 id=\"ember347\" class=\"ember-view\"><span class=\"ez-toc-section\" id=\"Cryptoagility\"><\/span>Cryptoagility<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p id=\"ember348\" class=\"ember-view reader-content-blocks__paragraph\"><strong>Cryptoagility <\/strong>refers to the ability of a system to switch quickly and efficiently from one cryptographic method or algorithm to another without compromising system functionality.<\/p>\n<p id=\"ember349\" class=\"ember-view reader-content-blocks__paragraph\">This capability becomes particularly important when cryptographic algorithms are compromised or deemed insecure.<\/p>\n<p id=\"ember350\" class=\"ember-view reader-content-blocks__paragraph\">Although cryptoagility in this specific case of CVE-2024-3094 is not directly related to the nature of the vulnerability, as the incident primarily affects the integrity and not the <strong>cryptography of the software<\/strong>, this <strong>security incident still<\/strong>highlights the overarching importance of cryptoagility for cybersecurity.<\/p>\n<p id=\"ember351\" class=\"ember-view reader-content-blocks__paragraph\">Only if we are able to switch software and hardware systems quickly and securely from one cryptographic method or algorithm to another can we use effective protection mechanisms.<\/p>\n<p id=\"ember352\" class=\"ember-view reader-content-blocks__paragraph\">In a constantly changing threat landscape, this is of crucial importance! Incidents like these &ndash; which in this form still lie undetected in some other software in a far higher number of unreported cases as malicious code &ndash; make it clear <strong>how essential flexible and robust IT security systems are<\/strong> for us to be able to react appropriately to unexpected security challenges.<\/p>\n<\/div><div class=\"fusion-text fusion-text-4\"><blockquote>\n<p>&ldquo;If an encryption mechanism or software is insecure, the clear motto is: deactivate and replace immediately!&rdquo; &ndash; Sascha Block &ndash; IT Architect<\/p>\n<\/blockquote>\n<p id=\"ember354\" class=\"ember-view reader-content-blocks__paragraph\">With attackers constantly developing new methods to circumvent security measures, cryptoagility is an effective protection mechanism that helps to increase resilience to such attacks. It enables organizations to implement adaptive security protocols that are prepared not only for current threats, but also for future threats. The events surrounding CVE-2024-3094 show that even supposedly secure components can be compromised, underlining the need to make the entire security infrastructure agile and adaptable.<\/p>\n<p id=\"ember355\" class=\"ember-view reader-content-blocks__paragraph\">To put it very clearly and unambiguously:<\/p>\n<blockquote>\n<p>&ldquo;You wouldn&rsquo;t get on a plane if it was proven that one of the engines was badly damaged, would you?<\/p>\n<\/blockquote>\n<\/div><div class=\"fusion-text fusion-text-5\"><p id=\"ember357\" class=\"ember-view reader-content-blocks__paragraph\">Neither should we rely on encryption mechanisms or software that have been identified as insecure.<\/p>\n<p id=\"ember358\" class=\"ember-view reader-content-blocks__paragraph\">Ensuring the security and integrity of our data means <strong>acting proactively <\/strong>and <strong>immediately decommissioning vulnerable systems <\/strong>and replacing them with secure alternatives.<\/p>\n<h3 id=\"ember359\" class=\"ember-view\"><span class=\"ez-toc-section\" id=\"Agile_security_strategies_instead_of_static_security_models\"><\/span>Agile security strategies instead of static security models<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p id=\"ember360\" class=\"ember-view reader-content-blocks__paragraph\">Furthermore, the incident emphasizes the importance of a comprehensive approach to security, which includes both the integrity of software and the robustness of cryptographic measures. As organizations move away from traditional, static security models to more dynamic, adaptive systems, cryptoagility will become a critical factor in maintaining data security and user trust.<\/p>\n<p id=\"ember361\" class=\"ember-view reader-content-blocks__paragraph\">Ultimately, the CVE-2024-3094 case serves as a reminder that information technology security requires an ongoing effort that includes both preventative and reactive strategies. Cryptoagility plays a central role here, as it enables security systems to be quickly adapted and strengthened in order to be prepared for newly discovered threats and vulnerabilities. In this sense, the promotion of cryptoagility is not only a technical necessity, but also a strategic imperative for all those who want to ensure security in the digital world.<\/p>\n<h3 id=\"ember362\" class=\"ember-view\"><span class=\"ez-toc-section\" id=\"Valuable_insights_that_we_can_take_away_with_us_and_implement_directly\"><\/span>Valuable insights that we can take away with us and implement directly:<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p id=\"ember363\" class=\"ember-view reader-content-blocks__paragraph\">From the incident with the critical backdoor vulnerability in the &ldquo;xz&rdquo; tools and libraries for Linux, we can gain several very valuable insights. These insights are not only relevant for IT security experts, but also for software developers, system administrators and IT management in order to minimize future security risks:<\/p>\n<ol>\n<li><strong>Importance of software integrity checks:<\/strong> The fact that the malicious code was found in official packages underscores the need for rigorous integrity checks and verification processes in software development and distribution.<\/li>\n<li><strong>Importance of open source security:<\/strong> As &ldquo;xz&rdquo; is a widely used open source tool, the incident shows the importance of security in open source projects. It emphasizes the need for contributions to be carefully examined, especially in projects that are used in critical infrastructures.<\/li>\n<li><strong>Rapid response to security incidents:<\/strong> The rapid identification and classification of the vulnerability as critical and the publication of updates and measures show how important a rapid response to security incidents is.<\/li>\n<li><strong>CVSS score as a useful assessment tool:<\/strong> The maximum CVSS score of 10\/10 indicates the critical nature of the vulnerability and serves as a guide for organizations to prioritize their response planning.<\/li>\n<li><strong>The role of the community and research:<\/strong> The discovery by Andre Freund and the subsequent communication with the relevant bodies and stakeholders around IT security emphasize the role of the security community and independent researchers in identifying and reporting vulnerabilities.<\/li>\n<li><strong>Awareness of supply chain attacks:<\/strong> The incident highlights the ongoing risk of supply chain attacks, where attackers compromise the supply chain of software and updates to spread malware.<\/li>\n<li><strong>The need for contingency plans and security checks:<\/strong> The recommendation to shut down or reset affected systems to secure versions demonstrates the importance of contingency plans and the ability to respond quickly and effectively to security threats.<\/li>\n<li><strong>Communication and transparency in the event of security incidents:<\/strong> Open communication about the vulnerability, affected versions and remediation measures is crucial for user trust and security.<\/li>\n<li><strong>Diversification and redundancy in software dependencies:<\/strong> The impact of specific distributions underscores the need to diversify dependencies and create redundancies to minimize downtime risks.<\/li>\n<li><strong>Importance of continuous monitoring and updates:<\/strong> The incident illustrates how important it is to continuously monitor systems and carry out regular updates in order to be prepared for newly discovered security vulnerabilities.<\/li>\n<\/ol>\n<h3 id=\"ember365\" class=\"ember-view\"><span class=\"ez-toc-section\" id=\"Open_source_myth_debunked_Why_transparency_in_the_software_world_automatically_means_security\"><\/span>Open source myth debunked: Why transparency in the software world automatically means security<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p id=\"ember366\" class=\"ember-view reader-content-blocks__paragraph\">The conclusion that open source software (OSS) is fundamentally insecure is based on a widespread misunderstanding of the nature and security dynamics of open source projects.<\/p>\n<p id=\"ember367\" class=\"ember-view reader-content-blocks__paragraph\">My key arguments illustrate why this conclusion is wrong:<\/p>\n<h3 id=\"ember368\" class=\"ember-view\"><span class=\"ez-toc-section\" id=\"Transparency_promotes_security\"><\/span>Transparency promotes security<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p id=\"ember369\" class=\"ember-view reader-content-blocks__paragraph\">Open source software is characterized by its transparency. The source code can be viewed by everyone, which enables a broad review by the community. Vulnerabilities can be discovered and reported by anyone, resulting in faster identification and resolution of vulnerabilities than in many closed-source environments where the code is only accessible to a limited group of developers.<\/p>\n<h3 id=\"ember370\" class=\"ember-view\"><span class=\"ez-toc-section\" id=\"Joint_effort\"><\/span>Joint effort<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p id=\"ember371\" class=\"ember-view reader-content-blocks__paragraph\">The security of OSS is often supported by an active and engaged community that regularly contributes in the form of patches, security updates and improvements. This collective effort leads to a continuous improvement in software quality and security.<\/p>\n<h3 id=\"ember372\" class=\"ember-view\"><span class=\"ez-toc-section\" id=\"Safety_audits_and_reviews\"><\/span>Safety audits and reviews<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p id=\"ember373\" class=\"ember-view reader-content-blocks__paragraph\">Many open source projects undergo regular security audits and reviews by experts. Large, widely used open source projects often receive additional security resources from companies that depend on the software, leading to even higher security scrutiny.<\/p>\n<h3 id=\"ember374\" class=\"ember-view\"><span class=\"ez-toc-section\" id=\"False_equation_of_availability_and_vulnerability\"><\/span>False equation of availability and vulnerability<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p id=\"ember375\" class=\"ember-view reader-content-blocks__paragraph\">The misconception that the availability of source code automatically leads to greater vulnerability ignores the fact that security is not achieved through obscurity, but through robust design and development practices. History has shown that many closed-source systems can also have serious security vulnerabilities, but the lack of transparency slows down their discovery and elimination.<\/p>\n<h3 id=\"ember376\" class=\"ember-view\"><span class=\"ez-toc-section\" id=\"Use_in_safety-critical_systems\"><\/span>Use in safety-critical systems<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p id=\"ember377\" class=\"ember-view reader-content-blocks__paragraph\">Open source software is used in a wide range of security-critical applications, from operating systems and network infrastructures to cryptographic libraries. The broad acceptance and use in these areas underlines the confidence in the security of open source software.<\/p>\n<h3 id=\"ember378\" class=\"ember-view\"><span class=\"ez-toc-section\" id=\"Example_of_successful_OSS_security_models\"><\/span>Example of successful OSS security models<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p id=\"ember379\" class=\"ember-view reader-content-blocks__paragraph\">Examples such as the Linux operating system, the OpenSSL encryption <a href=\"https:\/\/rock-the-prototype.com\/en\/learn-programming\/library\/\" target=\"_blank\" title=\"A library refers to a software library as a ready-made collection of code that can be used to perform general software development tasks. Libraries are essentially a collection of functions and procedures that can be called up by other software programs to execute certain functions.\" class=\"encyclopedia\">library<\/a> or the Apache web server software project show that open source software can not only be secure, but is often a leader in the implementation of security standards and practices.<\/p>\n<h3 id=\"ember380\" class=\"ember-view\"><span class=\"ez-toc-section\" id=\"Your_click_our_common_path_How_your_support_shapes_our_digital_future\"><\/span>Your click, our common path: How your support shapes our digital future<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p id=\"ember381\" class=\"ember-view reader-content-blocks__paragraph\">Stay tuned, my <strong>Rock the Prototype<\/strong> format provides you with free <strong>valuable knowledge<\/strong> on crucial <strong>tech topics<\/strong> in <strong>software development and<\/strong>their social impact.<\/p>\n<p id=\"ember382\" class=\"ember-view reader-content-blocks__paragraph\"><strong>Please support me<\/strong> with your <strong>subscription<\/strong> to my <a href=\"https:\/\/lnkd.in\/exv82i4M\" target=\"_blank\" rel=\"noopener\"><br>\n  <strong>Linkedin Newsletter<\/strong><br>\n<\/a><strong>podcast<\/strong> &amp; <a href=\"https:\/\/www.youtube.com\/@Rock-the-Prototype\" target=\"_blank\" rel=\"noopener\"><strong>YouTube<\/strong> <\/a><strong>channel.<\/strong> Of course I am also looking forward to <strong>your<\/strong> <strong>feedback<\/strong>, <strong>comments<\/strong> and <strong>likes<\/strong>!<\/p>\n<\/div><div class=\"fusion-text fusion-text-6\"><p id=\"ember383\" class=\"ember-view reader-content-blocks__paragraph\">My <a href=\"https:\/\/lnkd.in\/exv82i4M\" target=\"_blank\" rel=\"noopener\"><br>\n  <strong>Linkedin Newsletter<\/strong><br>\n<\/a> provides you, as always, with relevant knowledge and offers a compact overview.<\/p>\n<p id=\"ember384\" class=\"ember-view reader-content-blocks__paragraph\">Compact information &ndash; easy to understand!<\/p>\n<p id=\"ember385\" class=\"ember-view reader-content-blocks__paragraph\">Until then, stay safe, creative and above all curious!<\/p>\n<p id=\"ember386\" class=\"ember-view reader-content-blocks__paragraph\">Your Sascha Block<\/p>\n<\/div><\/div><\/div><\/div><\/div><div class=\"fusion-fullwidth fullwidth-box fusion-builder-row-2 fusion-flex-container has-pattern-background has-mask-background nonhundred-percent-fullwidth non-hundred-percent-height-scrolling\" style=\"--awb-border-radius-top-left:0px;--awb-border-radius-top-right:0px;--awb-border-radius-bottom-right:0px;--awb-border-radius-bottom-left:0px;--awb-flex-wrap:wrap;\"><div class=\"fusion-builder-row fusion-row fusion-flex-align-items-flex-start fusion-flex-content-wrap\" style=\"max-width:1144px;margin-left: calc(-4% \/ 2 );margin-right: calc(-4% \/ 2 );\"><div class=\"fusion-layout-column fusion_builder_column fusion-builder-column-1 fusion_builder_column_1_1 1_1 fusion-flex-column\" style=\"--awb-bg-size:cover;--awb-width-large:100%;--awb-margin-top-large:0px;--awb-spacing-right-large:1.92%;--awb-margin-bottom-large:0px;--awb-spacing-left-large:1.92%;--awb-width-medium:100%;--awb-order-medium:0;--awb-spacing-right-medium:1.92%;--awb-spacing-left-medium:1.92%;--awb-width-small:100%;--awb-order-small:0;--awb-spacing-right-small:1.92%;--awb-spacing-left-small:1.92%;\"><div class=\"fusion-column-wrapper fusion-column-has-shadow fusion-flex-justify-content-flex-start fusion-content-layout-column\"><a class=\"fusion-modal-text-link\" data-toggle=\"modal\" data-target=\".fusion-modal.Rock the Prototype - Softwareentwicklung &amp; Prototyping Podcast iTunes\" href=\"#\"><iframe id=\"embedPlayer\" style=\"width: 100%; max-width: 990px; overflow: hidden; border-radius: 10px; transform: translateZ(0px); animation: 2s ease 0s 6 normal none running loading-indicator; background-color: #e4e4e4;\" src=\"https:\/\/embed.podcasts.apple.com\/de\/podcast\/rock-the-prototype-softwareentwicklung-prototyping\/id1684107786?itsct=podcast_box_player&amp;itscg=30200&amp;ls=1&amp;theme=dark\" height=\"450px\" frameborder=\"0\" sandbox=\"allow-forms allow-popups allow-same-origin allow-scripts allow-top-navigation-by-user-activation\"><\/iframe> <\/a><\/div><\/div><\/div><\/div>\n<div class=\"fusion-fullwidth fullwidth-box fusion-builder-row-3 fusion-flex-container has-pattern-background has-mask-background nonhundred-percent-fullwidth non-hundred-percent-height-scrolling\" style=\"--awb-border-radius-top-left:0px;--awb-border-radius-top-right:0px;--awb-border-radius-bottom-right:0px;--awb-border-radius-bottom-left:0px;--awb-flex-wrap:wrap;\"><div class=\"fusion-builder-row fusion-row fusion-flex-align-items-flex-start fusion-flex-content-wrap\" style=\"max-width:1144px;margin-left: calc(-4% \/ 2 );margin-right: calc(-4% \/ 2 );\"><div class=\"fusion-layout-column fusion_builder_column fusion-builder-column-2 fusion_builder_column_1_3 1_3 fusion-flex-column\" style=\"--awb-bg-size:cover;--awb-width-large:33.333333333333%;--awb-margin-top-large:0px;--awb-spacing-right-large:5.76%;--awb-margin-bottom-large:0px;--awb-spacing-left-large:5.76%;--awb-width-medium:100%;--awb-order-medium:0;--awb-spacing-right-medium:1.92%;--awb-spacing-left-medium:1.92%;--awb-width-small:100%;--awb-order-small:0;--awb-spacing-right-small:1.92%;--awb-spacing-left-small:1.92%;\"><div class=\"fusion-column-wrapper fusion-column-has-shadow fusion-flex-justify-content-flex-start fusion-content-layout-column\"><div class=\"fusion-title title fusion-title-1 fusion-sep-none fusion-title-text fusion-title-size-two\" style=\"--awb-margin-top-small:30px;--awb-margin-right-small:0px;--awb-margin-bottom-small:20px;--awb-margin-left-small:0px;\"><h2 class=\"fusion-title-heading title-heading-left fusion-responsive-typography-calculated\" style=\"margin:0;--fontSize:30;line-height:1.1;\">&Uuml;ber den Autor:<\/h2><\/div><div class=\"fusion-image-element\" style=\"--awb-caption-title-font-family:var(--h2_typography-font-family);--awb-caption-title-font-weight:var(--h2_typography-font-weight);--awb-caption-title-font-style:var(--h2_typography-font-style);--awb-caption-title-size:var(--h2_typography-font-size);--awb-caption-title-transform:var(--h2_typography-text-transform);--awb-caption-title-line-height:var(--h2_typography-line-height);--awb-caption-title-letter-spacing:var(--h2_typography-letter-spacing);\"><span class=\" fusion-imageframe imageframe-none imageframe-1 hover-type-none\"><img decoding=\"async\" width=\"1920\" height=\"1920\" title=\"Sascha Block &ndash; Rock the Prototype\" src=\"https:\/\/rock-the-prototype.com\/wp-content\/uploads\/2019\/09\/Sascha_Block.jpg\" alt class=\"img-responsive wp-image-3342\" srcset=\"https:\/\/rock-the-prototype.com\/wp-content\/uploads\/2019\/09\/Sascha_Block-200x200.jpg 200w, https:\/\/rock-the-prototype.com\/wp-content\/uploads\/2019\/09\/Sascha_Block-400x400.jpg 400w, https:\/\/rock-the-prototype.com\/wp-content\/uploads\/2019\/09\/Sascha_Block-600x600.jpg 600w, https:\/\/rock-the-prototype.com\/wp-content\/uploads\/2019\/09\/Sascha_Block-800x800.jpg 800w, https:\/\/rock-the-prototype.com\/wp-content\/uploads\/2019\/09\/Sascha_Block-1200x1200.jpg 1200w, https:\/\/rock-the-prototype.com\/wp-content\/uploads\/2019\/09\/Sascha_Block.jpg 1920w\" sizes=\"(max-width: 1024px) 100vw, (max-width: 640px) 100vw, 400px\"><\/span><\/div><\/div><\/div><div class=\"fusion-layout-column fusion_builder_column fusion-builder-column-3 fusion_builder_column_2_3 2_3 fusion-flex-column\" style=\"--awb-bg-size:cover;--awb-width-large:66.666666666667%;--awb-margin-top-large:0px;--awb-spacing-right-large:2.88%;--awb-margin-bottom-large:0px;--awb-spacing-left-large:2.88%;--awb-width-medium:100%;--awb-order-medium:0;--awb-spacing-right-medium:1.92%;--awb-spacing-left-medium:1.92%;--awb-width-small:100%;--awb-order-small:0;--awb-spacing-right-small:1.92%;--awb-spacing-left-small:1.92%;\"><div class=\"fusion-column-wrapper fusion-column-has-shadow fusion-flex-justify-content-flex-start fusion-content-layout-column\"><div class=\"fusion-title title fusion-title-2 fusion-sep-none fusion-title-text fusion-title-size-three\" style=\"--awb-margin-top-small:30px;--awb-margin-right-small:0px;--awb-margin-bottom-small:20px;--awb-margin-left-small:0px;\"><h3 class=\"fusion-title-heading title-heading-left fusion-responsive-typography-calculated\" style=\"margin:0;--fontSize:26;line-height:1.2;\">Sascha Block<\/h3><\/div><div class=\"fusion-text fusion-text-7\"><p>Ich bin&nbsp;<a href=\"https:\/\/www.linkedin.com\/in\/sascha-block-5785b9126\/\">Sascha Block<\/a> &ndash; IT-Architekt in Hamburg und der Initiator von Rock the Prototype. Ich m&ouml;chte <a href=\"https:\/\/rock-the-prototype.com\/en\/prototyping-en\/prototyping\/\" target=\"_blank\" title=\"What is prototyping? Prototyping is both a process and a strategy for realizing ideas as quickly as possible.\" class=\"encyclopedia\">Prototyping<\/a> erlernbar und erfahrbar machen. Mit der Motivation Ideen prototypisch zu verwirklichen und Wissen rund um Software-Prototyping, Softwarearchitektur und Programmierung zu teilen, habe ich das Format und die Open-Source Initiative Rock the Prototype geschaffen.<\/p>\n<\/div><div><a class=\"fusion-button button-flat fusion-button-default-size button-custom fusion-button-default button-1 fusion-button-default-span fusion-button-default-type\" style=\"--button_accent_color:#ffffff;--button_accent_hover_color:#00ffff;--button_border_hover_color:#4ab4ff;--button_gradient_top_color:var(--awb-color3);--button_gradient_bottom_color:var(--awb-color3);--button_gradient_top_color_hover:var(--awb-color2);--button_gradient_bottom_color_hover:var(--awb-color2);\" target=\"_blank\" rel=\"noopener noreferrer\" href=\"https:\/\/rock-the-prototype.com\/kuenstliche-intelligenz-ki\/kuenstliche-intelligenz-wie-funktioniert-chat-gpt\/\"><span class=\"fusion-button-text awb-button__text awb-button__text--default\">Wie funktioniert ChatGPT? <\/span><\/a><\/div><div class=\"fusion-separator fusion-full-width-sep\" style=\"align-self: center;margin-left: auto;margin-right: auto;width:100%;\"><\/div><ul style=\"--awb-size:18px;--awb-line-height:30.6px;--awb-icon-width:30.6px;--awb-icon-height:30.6px;--awb-icon-margin:12.6px;--awb-content-margin:43.2px;\" class=\"fusion-checklist fusion-checklist-1 fusion-checklist-default type-icons\"><li class=\"fusion-li-item\" style=\"\"><span class=\"icon-wrapper circle-no\"><i class=\"fusion-li-icon fa-link fas\" aria-hidden=\"true\"><\/i><\/span><div class=\"fusion-li-item-content\">\n<p><a href=\"https:\/\/rock-the-prototype.com\/\">rock-the-prototype.com<\/a><\/p>\n<\/div><\/li><\/ul><\/div><\/div><\/div><\/div>\n\n","protected":false},"excerpt":{"rendered":"<p>How robust software development practices and effective IT security monitoring protect us from the well-hidden dangers of the cyber world. Now that cyberattacks are becoming increasingly dangerous and regular and digital borders are becoming increasingly invisible, software integrity is taking on a whole new significance as a fundamental pillar of our cybersecurity. This can never be shown more clearly than in the current xz backdoor incident. The invisible attackers not only expose the vulnerability of our digital infrastructures, but also bring an urgent question into focus:<br \/>\n&#8220;How can we effectively protect ourselves against the shadow work of cyber criminals?&#8221;<\/p>\n","protected":false},"author":1,"featured_media":4879,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_bbp_topic_count":0,"_bbp_reply_count":0,"_bbp_total_topic_count":0,"_bbp_total_reply_count":0,"_bbp_voice_count":0,"_bbp_anonymous_reply_count":0,"_bbp_topic_count_hidden":0,"_bbp_reply_count_hidden":0,"_bbp_forum_subforum_count":0,"footnotes":""},"categories":[1232],"tags":[],"class_list":["post-4880","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-it-security"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.2 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Invisible attacker via xz backdoor - IT Security &amp; Software Integrity<\/title>\n<meta name=\"description\" content=\"Why software integrity is our invisible shield against cyberattacks \u2705 xz Backdoor in Linux distribution \u2705 Understanding cryptoagility\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/rock-the-prototype.com\/en\/it-security\/invisible-attacker-via-xz-backdoor-it-security-software-integrity\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Invisible attacker via xz backdoor - IT Security &amp; Software Integrity\" \/>\n<meta property=\"og:description\" content=\"Why software integrity is our invisible shield against cyberattacks \u2705 xz Backdoor in Linux distribution \u2705 Understanding cryptoagility\" \/>\n<meta property=\"og:url\" content=\"https:\/\/rock-the-prototype.com\/en\/it-security\/invisible-attacker-via-xz-backdoor-it-security-software-integrity\/\" \/>\n<meta property=\"og:site_name\" content=\"Rock the Prototype - Softwareentwicklung &amp; Prototyping\" \/>\n<meta property=\"article:published_time\" content=\"2024-04-09T06:46:22+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2024-04-09T07:53:16+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/rock-the-prototype.com\/wp-content\/uploads\/2024\/04\/Unsichtbarer-Angreifer-via-xz-Backdoor-Warum-Softwareintegritaet-unser-unsichtbare-Schutzschild-gegen-Cyberangriffe-ist.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"1456\" \/>\n\t<meta property=\"og:image:height\" content=\"816\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Sascha Block\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@rocktheprototyp\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Sascha Block\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"14 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/rock-the-prototype.com\\\/en\\\/it-security\\\/invisible-attacker-via-xz-backdoor-it-security-software-integrity\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/rock-the-prototype.com\\\/en\\\/it-security\\\/invisible-attacker-via-xz-backdoor-it-security-software-integrity\\\/\"},\"author\":{\"name\":\"Sascha Block\",\"@id\":\"https:\\\/\\\/rock-the-prototype.com\\\/en\\\/#\\\/schema\\\/person\\\/fdb2f98edec62327712c2d26d981c081\"},\"headline\":\"Invisible attacker via xz backdoor &#8211; IT Security &amp; Software Integrity\",\"datePublished\":\"2024-04-09T06:46:22+00:00\",\"dateModified\":\"2024-04-09T07:53:16+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/rock-the-prototype.com\\\/en\\\/it-security\\\/invisible-attacker-via-xz-backdoor-it-security-software-integrity\\\/\"},\"wordCount\":2858,\"commentCount\":0,\"image\":{\"@id\":\"https:\\\/\\\/rock-the-prototype.com\\\/en\\\/it-security\\\/invisible-attacker-via-xz-backdoor-it-security-software-integrity\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/rock-the-prototype.com\\\/wp-content\\\/uploads\\\/2024\\\/04\\\/Unsichtbarer-Angreifer-via-xz-Backdoor-Warum-Softwareintegritaet-unser-unsichtbare-Schutzschild-gegen-Cyberangriffe-ist.jpg\",\"articleSection\":[\"IT Security\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/rock-the-prototype.com\\\/en\\\/it-security\\\/invisible-attacker-via-xz-backdoor-it-security-software-integrity\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/rock-the-prototype.com\\\/en\\\/it-security\\\/invisible-attacker-via-xz-backdoor-it-security-software-integrity\\\/\",\"url\":\"https:\\\/\\\/rock-the-prototype.com\\\/en\\\/it-security\\\/invisible-attacker-via-xz-backdoor-it-security-software-integrity\\\/\",\"name\":\"Invisible attacker via xz backdoor - IT Security & Software Integrity\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/rock-the-prototype.com\\\/en\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/rock-the-prototype.com\\\/en\\\/it-security\\\/invisible-attacker-via-xz-backdoor-it-security-software-integrity\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/rock-the-prototype.com\\\/en\\\/it-security\\\/invisible-attacker-via-xz-backdoor-it-security-software-integrity\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/rock-the-prototype.com\\\/wp-content\\\/uploads\\\/2024\\\/04\\\/Unsichtbarer-Angreifer-via-xz-Backdoor-Warum-Softwareintegritaet-unser-unsichtbare-Schutzschild-gegen-Cyberangriffe-ist.jpg\",\"datePublished\":\"2024-04-09T06:46:22+00:00\",\"dateModified\":\"2024-04-09T07:53:16+00:00\",\"author\":{\"@id\":\"https:\\\/\\\/rock-the-prototype.com\\\/en\\\/#\\\/schema\\\/person\\\/fdb2f98edec62327712c2d26d981c081\"},\"description\":\"Why software integrity is our invisible shield against cyberattacks \u2705 xz Backdoor in Linux distribution \u2705 Understanding cryptoagility\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/rock-the-prototype.com\\\/en\\\/it-security\\\/invisible-attacker-via-xz-backdoor-it-security-software-integrity\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/rock-the-prototype.com\\\/en\\\/it-security\\\/invisible-attacker-via-xz-backdoor-it-security-software-integrity\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/rock-the-prototype.com\\\/en\\\/it-security\\\/invisible-attacker-via-xz-backdoor-it-security-software-integrity\\\/#primaryimage\",\"url\":\"https:\\\/\\\/rock-the-prototype.com\\\/wp-content\\\/uploads\\\/2024\\\/04\\\/Unsichtbarer-Angreifer-via-xz-Backdoor-Warum-Softwareintegritaet-unser-unsichtbare-Schutzschild-gegen-Cyberangriffe-ist.jpg\",\"contentUrl\":\"https:\\\/\\\/rock-the-prototype.com\\\/wp-content\\\/uploads\\\/2024\\\/04\\\/Unsichtbarer-Angreifer-via-xz-Backdoor-Warum-Softwareintegritaet-unser-unsichtbare-Schutzschild-gegen-Cyberangriffe-ist.jpg\",\"width\":1456,\"height\":816,\"caption\":\"Unsichtbarer Angreifer via xz Backdoor - Warum Softwareintegrit\u00e4t unser unsichtbare Schutzschild gegen Cyberangriffe ist\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/rock-the-prototype.com\\\/en\\\/it-security\\\/invisible-attacker-via-xz-backdoor-it-security-software-integrity\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Startseite\",\"item\":\"https:\\\/\\\/rock-the-prototype.com\\\/en\\\/rock-the-prototype\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Invisible attacker via xz backdoor &#8211; IT Security &amp; Software Integrity\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/rock-the-prototype.com\\\/en\\\/#website\",\"url\":\"https:\\\/\\\/rock-the-prototype.com\\\/en\\\/\",\"name\":\"Rock the Prototype - Softwareentwicklung &amp; Prototyping\",\"description\":\"Prototyping: Software Prototypen, Software entwickeln &amp; Programmieren im Team\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/rock-the-prototype.com\\\/en\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/rock-the-prototype.com\\\/en\\\/#\\\/schema\\\/person\\\/fdb2f98edec62327712c2d26d981c081\",\"name\":\"Sascha Block\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/967c419542686b085600443beafb2e55ad1ef6532a0ad9b96d244cb24fd8c117?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/967c419542686b085600443beafb2e55ad1ef6532a0ad9b96d244cb24fd8c117?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/967c419542686b085600443beafb2e55ad1ef6532a0ad9b96d244cb24fd8c117?s=96&d=mm&r=g\",\"caption\":\"Sascha Block\"},\"description\":\"Ich bin Sascha Block \u2013 IT-Architekt in Hamburg und der Initiator von Rock the Prototype. Ich m\u00f6chte Prototyping erlernbar und erfahrbar machen. Mit der Motivation Ideen prototypisch zu verwirklichen und Wissen rund um Software-Prototyping, Softwarearchitektur und Softwareentwicklung zu teilen, habe ich das Format und die Open-Source Initiative Rock the Prototype geschaffen.\",\"sameAs\":[\"https:\\\/\\\/rock-the-prototype.com\",\"https:\\\/\\\/www.instagram.com\\\/rock_the_prototype\\\/\",\"https:\\\/\\\/x.com\\\/rocktheprototyp\",\"https:\\\/\\\/www.youtube.com\\\/@Rock-the-Prototype\\\/\"],\"url\":\"https:\\\/\\\/rock-the-prototype.com\\\/en\\\/author\\\/administrator-2\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Invisible attacker via xz backdoor - IT Security & Software Integrity","description":"Why software integrity is our invisible shield against cyberattacks \u2705 xz Backdoor in Linux distribution \u2705 Understanding cryptoagility","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/rock-the-prototype.com\/en\/it-security\/invisible-attacker-via-xz-backdoor-it-security-software-integrity\/","og_locale":"en_US","og_type":"article","og_title":"Invisible attacker via xz backdoor - IT Security & Software Integrity","og_description":"Why software integrity is our invisible shield against cyberattacks \u2705 xz Backdoor in Linux distribution \u2705 Understanding cryptoagility","og_url":"https:\/\/rock-the-prototype.com\/en\/it-security\/invisible-attacker-via-xz-backdoor-it-security-software-integrity\/","og_site_name":"Rock the Prototype - Softwareentwicklung &amp; Prototyping","article_published_time":"2024-04-09T06:46:22+00:00","article_modified_time":"2024-04-09T07:53:16+00:00","og_image":[{"width":1456,"height":816,"url":"https:\/\/rock-the-prototype.com\/wp-content\/uploads\/2024\/04\/Unsichtbarer-Angreifer-via-xz-Backdoor-Warum-Softwareintegritaet-unser-unsichtbare-Schutzschild-gegen-Cyberangriffe-ist.jpg","type":"image\/jpeg"}],"author":"Sascha Block","twitter_card":"summary_large_image","twitter_creator":"@rocktheprototyp","twitter_misc":{"Written by":"Sascha Block","Est. reading time":"14 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/rock-the-prototype.com\/en\/it-security\/invisible-attacker-via-xz-backdoor-it-security-software-integrity\/#article","isPartOf":{"@id":"https:\/\/rock-the-prototype.com\/en\/it-security\/invisible-attacker-via-xz-backdoor-it-security-software-integrity\/"},"author":{"name":"Sascha Block","@id":"https:\/\/rock-the-prototype.com\/en\/#\/schema\/person\/fdb2f98edec62327712c2d26d981c081"},"headline":"Invisible attacker via xz backdoor &#8211; IT Security &amp; Software Integrity","datePublished":"2024-04-09T06:46:22+00:00","dateModified":"2024-04-09T07:53:16+00:00","mainEntityOfPage":{"@id":"https:\/\/rock-the-prototype.com\/en\/it-security\/invisible-attacker-via-xz-backdoor-it-security-software-integrity\/"},"wordCount":2858,"commentCount":0,"image":{"@id":"https:\/\/rock-the-prototype.com\/en\/it-security\/invisible-attacker-via-xz-backdoor-it-security-software-integrity\/#primaryimage"},"thumbnailUrl":"https:\/\/rock-the-prototype.com\/wp-content\/uploads\/2024\/04\/Unsichtbarer-Angreifer-via-xz-Backdoor-Warum-Softwareintegritaet-unser-unsichtbare-Schutzschild-gegen-Cyberangriffe-ist.jpg","articleSection":["IT Security"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/rock-the-prototype.com\/en\/it-security\/invisible-attacker-via-xz-backdoor-it-security-software-integrity\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/rock-the-prototype.com\/en\/it-security\/invisible-attacker-via-xz-backdoor-it-security-software-integrity\/","url":"https:\/\/rock-the-prototype.com\/en\/it-security\/invisible-attacker-via-xz-backdoor-it-security-software-integrity\/","name":"Invisible attacker via xz backdoor - IT Security & Software Integrity","isPartOf":{"@id":"https:\/\/rock-the-prototype.com\/en\/#website"},"primaryImageOfPage":{"@id":"https:\/\/rock-the-prototype.com\/en\/it-security\/invisible-attacker-via-xz-backdoor-it-security-software-integrity\/#primaryimage"},"image":{"@id":"https:\/\/rock-the-prototype.com\/en\/it-security\/invisible-attacker-via-xz-backdoor-it-security-software-integrity\/#primaryimage"},"thumbnailUrl":"https:\/\/rock-the-prototype.com\/wp-content\/uploads\/2024\/04\/Unsichtbarer-Angreifer-via-xz-Backdoor-Warum-Softwareintegritaet-unser-unsichtbare-Schutzschild-gegen-Cyberangriffe-ist.jpg","datePublished":"2024-04-09T06:46:22+00:00","dateModified":"2024-04-09T07:53:16+00:00","author":{"@id":"https:\/\/rock-the-prototype.com\/en\/#\/schema\/person\/fdb2f98edec62327712c2d26d981c081"},"description":"Why software integrity is our invisible shield against cyberattacks \u2705 xz Backdoor in Linux distribution \u2705 Understanding cryptoagility","breadcrumb":{"@id":"https:\/\/rock-the-prototype.com\/en\/it-security\/invisible-attacker-via-xz-backdoor-it-security-software-integrity\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/rock-the-prototype.com\/en\/it-security\/invisible-attacker-via-xz-backdoor-it-security-software-integrity\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/rock-the-prototype.com\/en\/it-security\/invisible-attacker-via-xz-backdoor-it-security-software-integrity\/#primaryimage","url":"https:\/\/rock-the-prototype.com\/wp-content\/uploads\/2024\/04\/Unsichtbarer-Angreifer-via-xz-Backdoor-Warum-Softwareintegritaet-unser-unsichtbare-Schutzschild-gegen-Cyberangriffe-ist.jpg","contentUrl":"https:\/\/rock-the-prototype.com\/wp-content\/uploads\/2024\/04\/Unsichtbarer-Angreifer-via-xz-Backdoor-Warum-Softwareintegritaet-unser-unsichtbare-Schutzschild-gegen-Cyberangriffe-ist.jpg","width":1456,"height":816,"caption":"Unsichtbarer Angreifer via xz Backdoor - Warum Softwareintegrit\u00e4t unser unsichtbare Schutzschild gegen Cyberangriffe ist"},{"@type":"BreadcrumbList","@id":"https:\/\/rock-the-prototype.com\/en\/it-security\/invisible-attacker-via-xz-backdoor-it-security-software-integrity\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Startseite","item":"https:\/\/rock-the-prototype.com\/en\/rock-the-prototype\/"},{"@type":"ListItem","position":2,"name":"Invisible attacker via xz backdoor &#8211; IT Security &amp; Software Integrity"}]},{"@type":"WebSite","@id":"https:\/\/rock-the-prototype.com\/en\/#website","url":"https:\/\/rock-the-prototype.com\/en\/","name":"Rock the Prototype - Softwareentwicklung &amp; Prototyping","description":"Prototyping: Software Prototypen, Software entwickeln &amp; Programmieren im Team","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/rock-the-prototype.com\/en\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Person","@id":"https:\/\/rock-the-prototype.com\/en\/#\/schema\/person\/fdb2f98edec62327712c2d26d981c081","name":"Sascha Block","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/967c419542686b085600443beafb2e55ad1ef6532a0ad9b96d244cb24fd8c117?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/967c419542686b085600443beafb2e55ad1ef6532a0ad9b96d244cb24fd8c117?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/967c419542686b085600443beafb2e55ad1ef6532a0ad9b96d244cb24fd8c117?s=96&d=mm&r=g","caption":"Sascha Block"},"description":"Ich bin Sascha Block \u2013 IT-Architekt in Hamburg und der Initiator von Rock the Prototype. Ich m\u00f6chte Prototyping erlernbar und erfahrbar machen. Mit der Motivation Ideen prototypisch zu verwirklichen und Wissen rund um Software-Prototyping, Softwarearchitektur und Softwareentwicklung zu teilen, habe ich das Format und die Open-Source Initiative Rock the Prototype geschaffen.","sameAs":["https:\/\/rock-the-prototype.com","https:\/\/www.instagram.com\/rock_the_prototype\/","https:\/\/x.com\/rocktheprototyp","https:\/\/www.youtube.com\/@Rock-the-Prototype\/"],"url":"https:\/\/rock-the-prototype.com\/en\/author\/administrator-2\/"}]}},"_links":{"self":[{"href":"https:\/\/rock-the-prototype.com\/en\/wp-json\/wp\/v2\/posts\/4880","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/rock-the-prototype.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/rock-the-prototype.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/rock-the-prototype.com\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/rock-the-prototype.com\/en\/wp-json\/wp\/v2\/comments?post=4880"}],"version-history":[{"count":3,"href":"https:\/\/rock-the-prototype.com\/en\/wp-json\/wp\/v2\/posts\/4880\/revisions"}],"predecessor-version":[{"id":4883,"href":"https:\/\/rock-the-prototype.com\/en\/wp-json\/wp\/v2\/posts\/4880\/revisions\/4883"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/rock-the-prototype.com\/en\/wp-json\/wp\/v2\/media\/4879"}],"wp:attachment":[{"href":"https:\/\/rock-the-prototype.com\/en\/wp-json\/wp\/v2\/media?parent=4880"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/rock-the-prototype.com\/en\/wp-json\/wp\/v2\/categories?post=4880"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/rock-the-prototype.com\/en\/wp-json\/wp\/v2\/tags?post=4880"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}