Science and technology | Hacking the internet

A stealth attack came close to compromising the world’s computers

The cyber-scare shows why the internet’s crowdsourced code is vulnerable

A sequence of alternating 1s and 0s arranged in a pattern, interrupted by a pair of mysterious eyes in the center, peering out from the arrangement of digits.
Illustration: Mike Haddad

In 2020 XKCD, a popular online comic strip, published a cartoon depicting a teetering arrangement of blocks with the label: “all modern digital infrastructure”. Perched precariously at the bottom, holding everything up, was a lone, slender brick: “A project some random person in Nebraska has been thanklessly maintaining since 2003.” The illustration quickly became a cult classic among the technically minded, for it highlighted a harsh truth: the software at the heart of the internet is maintained not by giant corporations or sprawling bureaucracies but by a handful of earnest volunteers toiling in obscurity. A cyber-security scare in recent days shows how the result can be near-disaster.

On March 29th Andres Freund, an engineer at Microsoft, published a short detective story. In recent weeks he had noticed that SSH—a system to log on securely to another device over the internet—was running about 500 milliseconds more slowly than expected. Closer inspection revealed malicious code embedded deep inside XZ Utils, some software designed to compress data used inside the Linux operating system, which runs on virtually all publicly accessible internet servers. Those servers ultimately undergird the internet, including vital financial and government services. The malicious code would have served as a “master key”, allowing attackers to steal encrypted data or plant other malware.

Explore more

This article appeared in the Science & technology section of the print edition under the headline “Cyber-scary”

China’s risky reboot

From the April 6th 2024 edition

Discover stories from this section and more in the list of contents

Explore the edition

More from Science and technology

How Ukraine’s new tech foils Russian aerial attacks

It is pioneering acoustic detection, with surprising success

The deep sea is home to “dark oxygen”

Nodules on the seabed, rather than photosynthesis, are the source of the gas


Augmented reality offers a safer driving experience

Complete with holograms on the windscreen


Clues to a possible cure for AIDS

Doctors, scientists and activists meet to discuss how to pummel HIV

AI can predict tipping points before they happen

Potential applications span from economics to epidemiology

Astronomers have found a cave on the moon

Such structures could serve as habitats for future astronauts