A backdoor in a popular Linux application puts the entire free software community on alert. The latest version of the xz Util application included in its source code several routines intended to weaken the encryption of SSH connections.

It was a deliberate attack, planned for quite some time and it almost worked. The original developer had begun to hand over part of the control of the application's development in recent years to other collaborators on the project, including Jia Tan, who had worked on it for years.