In this episode, Josh and Otto dive into the world of Debian packaging, exploring the challenges of supply chain security and the importance of transparency in open source projects. They discuss Otto’s blog post about the XZ backdoor and how it’s a nearly impossible attack to detect. Otto does a great job breaking down an incredibly complex problem into understandable pieces. Episode Links Otto Could the XZ backdoor have been detected with better Git and Debian packaging practices? This episode is also available as a podcast, search for “Open Source Security” on your favorite podcast player. ...