I have watched a few videos talking about the XZ attack and how a backdoor was opened up via very clever stages of obfuscation. Sorry if my questions come across as basic, but from what I understand, it made it to "upstream" so does that mean eventually Debian stable could have started using the latest version of XZ, opening the backdoor to millions of computers without the world even knowing about it?
Also, I am trying to understand how a "compiled tarball" is different from the source code shown on GitHub? You have to download the repo from GitHub and compile the tarball yourself? Is it normal for something to be corrupted and have two versions, a small version and a large version, as they were labeled, or was this disguised as something that XZ would typically do as a unit test, so nobody really thought anything of it? (Unit testing is normal for taball compilation?) Lots more to it than just this but I understand the corrupted tarball as the first step towards silently injecting the next step using some more clever techniques that flew under the radar.
SOCIAL SHARE CARD GENERATOR