What does wolfSSL do to mitigate against attacks similar to the xz/liblzma malware in OpenSSH?
A recent backdoor breach in Debian SSH connections, facilitated by an adversarial code contribution to the xz/liblzma project[1], underscores the need for rigorous vetting of code, contributors and intent. wolfSSL Inc. implements stringent procedures to prevent scenarios like malicious code merges.
For non-employee code contributors:
Read more