Linked by Jordan Spencer Cunningham on Mon 14th Jun 2010 23:58 UTC
Permalink for comment 430036
To read all comments associated with this story, please click here.
To read all comments associated with this story, please click here.
News
Linked by Thom Holwerda on 05/23/13 23:22 UTC
Linked by Thom Holwerda on 05/23/13 22:04 UTC
Linked by Thom Holwerda on 05/23/13 22:01 UTC
Linked by Thom Holwerda on 05/23/13 17:52 UTC
Linked by Thom Holwerda on 05/22/13 22:23 UTC
Linked by Thom Holwerda on 05/22/13 13:38 UTC
Linked by Thom Holwerda on 05/22/13 13:30 UTC, submitted by JRepin
Linked by Thom Holwerda on 05/21/13 22:06 UTC
Linked by Thom Holwerda on 05/21/13 21:45 UTC
Linked by Thom Holwerda on 05/21/13 15:53 UTC
More News »
Sponsored Links



Member since:
2006-01-26
All the reports I've read about this so far play it off as a manipulated download file on several mirror sites (and their main site?).
I'm not sure why that would indicate that the source code was compromised (although, perhaps the download archive itself contains sources which were also messed with).
In any case, I think this clearly indicates a distribution weakness - and I don't think this is directly attributable to the open source nature of this project (which I'm sure is what many people are claiming). Similar malware could probably be easily attached to a closed source Windows/OS X binary package being distributed via untrusted mirrors or give non-trusted people access to your release area just as well.
Edited 2010-06-15 01:51 UTC