Volunteer Programmer Prevents Major Cyber Attack
In March 2024, a volunteer programmer, Andres Freund, discovered a malicious “backdoor” code which had been planted in Linux, the operating software used by the majority of the world’s web servers. If undetected, this backdoor could have resulted in a potentially devastating cyber attack by allowing attackers to steal encrypted data or plant malware on millions of computers worldwide.
Linux is used on the servers hosting most of the webpages on the internet, including Facebook, Google, Wikipedia, and the servers used by banks, hospitals, governments and Fortune 500 companies. The security of the software is therefore a matter of global importance. Despite this importance, Linux is predominantly maintained by a small group of volunteer programmers who fix bugs and patch holes in the software.
While conducting routine maintenance, Freund noticed an anomaly in an application on Linux called SSH, used to log into computers remotely, which was consuming excessive processing power. He traced the issue to a data compression toolset on Linux called XZ Utils, where he found the backdoor. This backdoor could have enabled attackers to control a user’s SSH connection and secretly execute code, potentially leading to data theft or malware installation. Freund promptly reported his findings to the open-source community and a fix was developed within hours.
Investigations revealed that the anonymous attacker had spent years assisting in the maintenance of XZ Utils to gain the trust of other developers, eventually becoming one of two official maintainers of XZ Utils, before planting the backdoor earlier this year.
This incident underscores the security risks inherent in our reliance on this potentially insecure, volunteer-maintained technology, which forms the backbone of the internet.
Author: Cristin Hunt 2023/2024 Articling Student-At-Law
Photo Credit: https://unsplash.com/@towfiqu999999
Expertise
Insights
-
Privacy and Data Protection
Canadian Privacy Regulators Publish Findings and Guidance on OpenAI Privacy Compliance
Following a multi-year joint investigation, federal and provincial privacy regulators recently published their findings with respect to OpenAI’s collection and use of personal information to train… -
Technology
Anthropic Prepares for Public Markets
Anthropic, one of the world’s leading AI firms, has confidentially submitted a draft S-1 registration statement to the U.S. Securities and Exchange Commission, paving the way for a potential initial… -
Technology
Blast-off: The Race to IPO in the American Technology Landscape
On May 20, 2026, Space Exploration Technologies Corp. (“SpaceX”) filed an S-1 form with the United States’ Securities and Exchange Commission, indicating its intention to launch an initial public… -
Technology
Humans: 0, Robot: 1 – Sony’s Project Ace Robot Beats the Pros
Developed by Sony AI, a new robot named Ace has outperformed elite table tennis players, marking a significant milestone in AI and robotics. While AI systems have previously rivalled or surpassed… -
Technology
TikTok Cleared to Continue Canadian Operations Following National Security Review
The Government of Canada (the “Government”) has concluded its most recent national security review of TikTok, the popular short-form video platform owned by Chinese technology company ByteDance Ltd… -
Technology
Confined Space Robotics Awarded $1.5M Contract to Automate Blast and Paint at Seaspan Shipyard
Confined Space Robotics (“CSR”) has been awarded a $1.5 million contract by Seaspan Shipyards to develop and integrate abrasive blast and paint robotic systems at Seaspan’s Vancouver shipyard. Seaspan…