i don’t understand how people see the xz incident and conclude that open source is insecure. That level of social engineering could easily have worked on a company as well, but it was detected *because* it was open source. All other mechanisms failed, and it was just some random guy poking around that discovered it. That kind of scrutiny doesn’t happen on closed source systems
@kellogh
Just remember the Solarwinds incident.
It was much easier for the attacker, took less time, and was only detected after the fact