Skip to content
DevMeme
5427 of 7590
Security Post #5949 · source on Telegram

The 'LGTM' That Almost Broke the Internet: The XZ Backdoor Incident

Description

A two-part meme composed of screenshots from Twitter (now X) user 'terminally onλine engineer' (@tekbog), documenting a real event from the XZ Utils backdoor incident. The first tweet, captioned 'xz backdoor code shipped with a good ol' LGTM', displays a GitHub screenshot showing a Google security engineer, Jonathan Metzman, approving and merging a commit with the simple comment 'lgtm' (Looks Good To Me). The second tweet, captioned 'respect for owning it', shows a subsequent comment from Metzman, where he reflects with humility: 'In hindsight, this does not "look good to me" :-)'. This meme captures a critical moment in a major cybersecurity event, highlighting the stark contrast between the casual nature of a routine code review and the severe, hidden threat of a sophisticated supply chain attack. It serves as a somber, humorous commentary on the pressures and potential fallibility of even experienced engineers and the fragility of the open-source ecosystem, while also acknowledging the importance of professional accountability

Comments

11
Anonymous ★ Top Pick The entire security model of the internet apparently hinges on whether the one engineer reviewing a critical dependency has had their morning coffee yet. LGTM
  1. Anonymous ★ Top Pick

    The entire security model of the internet apparently hinges on whether the one engineer reviewing a critical dependency has had their morning coffee yet. LGTM

  2. Anonymous

    Memo to reviewers: if your LGTM comment is shorter than the SHA you’re merging, you’re not approving code - you’re countersigning the attacker’s CLA

  3. Anonymous

    The most expensive four letters in software history: 'LGTM' on a backdoor that almost compromised the entire Linux ecosystem. Turns out the 'G' in LGTM sometimes stands for 'God help us all' when reviewing state-sponsored supply chain attacks disguised as performance improvements

  4. Anonymous

    Nothing says 'defense in depth' quite like a security engineer rubber-stamping a backdoor with 'lgtm' and merging it to master. The XZ backdoor incident perfectly encapsulates the modern software supply chain: we've automated everything except the part where humans actually read the code. At least the post-incident comment 'In hindsight, this does not look good to me' will make a great addition to the incident postmortem template - right next to 'TODO: actually review code before approving.' The real vulnerability wasn't in the code; it was trusting that a two-letter acronym constitutes due diligence for critical infrastructure dependencies

  5. Anonymous

    Apparently LGTM stands for "Looks Good To Malware" - 16 green checks validated formatting, not provenance; two‑person integrity, signed artifacts, and SLSA beat emoji‑driven reviews

  6. Anonymous

    LGTM: the OSS rubber stamp that turns supply chain audits into hindsight festivals

  7. Anonymous

    Nothing says supply-chain security like 16 green checks and an LGTM acting as the root CA

  8. @philipp_2nd 2y

    https://boehs.org/node/everything-i-know-about-the-xz-backdoor

  9. @lastdude 2y

    https://t.me/speak_in_English_group

  10. @litlpip 2y

    Tldr?

    1. Deleted Account 2y

      The dude who backdoored xz also disabled checks for that specific attack vector in google's fuzzing thingy; that guy accepted the pr with lgtm. Or smth like that

Use J and K for navigation