Best podcast episodes on the XZ Utils backdoor
On March 29, 2024, Andres Freund disclosed on the oss-security mailing list that XZ Utils versions 5.6.0 and 5.6.1 contained a backdoor that could lead to SSH server compromise. The malicious code sat in the release tarballs rather than the project's git source, and CISA advised users to downgrade to an uncompromised version (CVE-2024-3094).
Sources: openwall.com, cisa.gov
8 episodes from 6 shows. Dates and lengths are from each show's own feed.
- 01
CROC News - XZ Utils backdoor explained
· 13 min · Beginner
Thirteen minutes, recorded within days: the fastest way to understand what was found.
- 02
Microsoft Threat Intelligence Podcast
Behind the Scenes of the XZ vuln with Andres Freund and Thomas Roccia
· 33 min · Beginner
Andres Freund himself on how an SSH performance oddity led him to the backdoor.
- 03
· 61 min · Practitioner
An emergency episode from open source security veterans, explaining the basics while facts were still moving.
- 04
Costin Raiu joins the XZ Utils backdoor investigation
· 52 min · Expert
Costin Raiu digs into the timeline and the long-con tradecraft behind the attack.
- 05
XZ - Backdoors and The Fragile Supply Chain - PSW #823
· 172 min · Expert
The full Security Weekly crew breaks down the technical details at length; long, but thorough.
- 06
Lessons That The XZ Utils Backdoor Spells Out - Farshad Abasi - ASW #280
· 60 min · Practitioner
The appsec lessons: abuse of maintainer trust, obscured changes, and suppressed warnings.
- 07
· 72 min · Practitioner
Why undersupported maintainers are the real problem XZ exposed, and what consumers owe them.
- 08
Detecting XZ in Debian with Otto Kekäläinen
· 32 min · Expert
A Debian maintainer on why an attack like XZ is nearly impossible to catch at packaging time.