The #xz news broke while I was at con and almost entirely offline, and what posts I’ve seen are technical enough that I haven’t _entirely_ understood it (I’m a fairly knowledgeable generalist geek, but no programmer), but I’m starting to get the impression that this is something along the lines of a modern version of #CliffStoll’s #CuckoosEgg? One person finds a tiny flaw that, once dug into, becomes a big “holy shit this is bad” realization?