---
title: "decrypt verifies a signature on the server's host key by a fixed Ed448 key, and then passes a payload to system(). It's RCE, not auth bypass, and gated/unreplayable.\" — Bluesky"
url: https://daily.dev/posts/decrypt-verifies-a-signature-on-the-server-s-host-key-by-a-fixed-ed448-key-and-then-passes-a-payloa-zymrg0ag8
source_url: https://bsky.app/profile/filippo.abyssdomain.expert/post/3kowjkx2njy2b
type: article
source: "Hacker News"
published: 2024-03-30T22:21:48.813Z
updated: 2024-05-09T09:06:08.895Z
tags: ["security", "webdev", "cryptography", "reverse-engineering"]
reading_time: 1
upvotes: 2
comments: 0
language: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# decrypt verifies a signature on the server's host key by a fixed Ed448 key, and then passes a payload to system(). It's RCE, not auth bypass, and gated/unreplayable." — Bluesky

**[Hacker News](https://daily.dev/sources/hn)** · 1 min read · 2 upvotes · 0 comments

## Summary

A preliminary analysis reveals that the xz backdoor utilizes a fixed Ed448 key to verify the server's host key and then executes a payload through system(), resulting in remote code execution.

## Full article

daily.dev links to this article rather than hosting it. Read it at the original source: <https://bsky.app/profile/filippo.abyssdomain.expert/post/3kowjkx2njy2b>

## Similar posts on daily.dev

- [Don’t just attend KubeCon \+ CloudNativeCon, Merge Forward your experience\!](https://daily.dev/posts/don-t-just-attend-kubecon-cloudnativecon-merge-forward-your-experience--l0rpp73x8) · CNCF · 0 upvotes · 0 comments
- [Announcing H2 2026 KCDs](https://daily.dev/posts/announcing-h2-2026-kcds-m96goajm1) · CNCF · 1 upvotes · 0 comments
- [Two months of Open Community Groups](https://daily.dev/posts/two-months-of-open-community-groups-asf52zhbs) · CNCF · 0 upvotes · 0 comments

---

Tags: [#security](https://daily.dev/tags/security), [#webdev](https://daily.dev/tags/webdev), [#cryptography](https://daily.dev/tags/cryptography), [#reverse-engineering](https://daily.dev/tags/reverse-engineering)

[View this post on daily.dev](https://daily.dev/posts/decrypt-verifies-a-signature-on-the-server-s-host-key-by-a-fixed-ed448-key-and-then-passes-a-payloa-zymrg0ag8)
