Comment 13 for bug 1812353

Revision history for this message
Christoph Anton Mitterer (calestyo) wrote :

Hmm that's pretty bad then (which is not to be read as blaming you or anyone else here).

Are there going to be any… "consequences"?

I mean trying to find out whether systems have been compromised is probably impossible... an attacker could have used this long ago to basically do everything, from silently taking over end user systems to secretly injecting code in development repos.
Sure one can argue that this might have been noticed - but it also might have been not.

But is there a chance to e.g. get full audits of apt done by security experts?

I'd assume that aptitude was also fully affected by this, right?