In an April 2024 NPR All Things Considered interview, Microsoft software engineer Andres Freund says he was running routine tests of open-source software when he noticed something odd: SSH — the tool administrators use to control computers remotely — 'seemed to be using too much resources' on a machine where nobody was authorized to log in. The symptoms were 'weird enough that I couldn't really justify to myself to not switch' from his planned work to investigating.

Digging deeper, he found injected code in the open-source software that powers servers for governments, companies and banks — a backdoor letting someone log in without authorization. Whoever holds that access can do just about anything, he says: shut down banking systems, interrupt industrial controls, steal data. Freund recalls the injection took multiple years of work and more effort than a lone individual could manage.

The realization came slowly, he says; he kept assuming he must be wrong, then back to realizing it might actually be true. Once he sounded the alarm, developers piled on and fixed the flaw, and a cybersecurity expert said 'the world owes Andres unlimited free beer.'

For Freund the deeper problem is structural: the compromised component had been maintained by a single unpaid person for close to twenty years despite being used extremely widely. 'We got unreasonably lucky here, and we can't just bank on that going forward,' he says.

Detection came from the backdoor's own side effect — extra resource use in SSH logins — not from any security review or scan.

Freund's discipline was the differentiator: the symptom was small enough to ignore, and he switched his whole plan to chase it.

The catch depended on luck, by Freund's own account, which is why he argues maintainer funding must change, as it did after Heartbleed.

Small unexplained anomalies are cheap to chase and expensive to ignore. And infrastructure software should not rest on one unpaid maintainer for twenty years.

Once Freund reported it, the community moved fast: people piled on and the flaw was fixed, and he became an 'internet hero.' In the interview he points to Heartbleed as the model for what comes next — after that OpenSSL vulnerability, companies started paying maintainers so security could actually improve, 'and that has to happen more.'

FOLLOW THE EVIDENCE

The sources

  1. One engineer may have saved the world from a massive cyber attack npr.org