We are now at t+26h. Please compare how much we knew about the xz-attack after less than a day with what we know about the chain of events of giant outage yesterday.
If something similar had been caused by an OSS component, we would see congress discussing a ban on open software in critical infrastructure already.
If something similar had been caused by an OSS component, we would see congress discussing a ban on open software in critical infrastructure already.
No we won’t. I refer to HeartBleed, Log4J, and Eternal Blue, and Solar winds. None of those affected applications have been banned and never will. Congress bans are based on political aspects not technical ones.
Huawei ban is because of the ties to China, kaspersky was banned because of Russian ties.