| ▲ | sam_lowry_ 10 hours ago | |||||||||||||||||||||||||
This is exactly why OpenWRT has no unattended updates by default ) | ||||||||||||||||||||||||||
| ▲ | shoddydoordesk 10 hours ago | parent [-] | |||||||||||||||||||||||||
You are dismissing the seriousness of this. Their package manager is widely used. One would only need to compromise their build servers to wreak havoc. Didn't they have a vulnerability in their firmware download tool like a minute ago? The difference between OpenWRT and Linux distros is the amount of testing and visibility. OpenWRT is loaded on to residential devices and forgotten about, it doesn't have professional sysadmins babysitting it 24/7. Remember the xz backdoor was only discovered because some autist at Microsoft noticed a microsecond difference in performance testing. | ||||||||||||||||||||||||||
| ||||||||||||||||||||||||||