When was the last time you read an End User License Agreement before clicking “I agree”? And by that, I mean the entire EULA; not just skimming the bold disclaimer at the top and scrolling past it all to get to the confirmation button as fast as you can. I mean, when have you actually read it?
Almost nobody does. And those who occasionally try, usually abandon the effort around clause fourteen because the exercise feels like a nonsense formality: a wall of legalese designed to be accepted, not to be understood. It’s the digital equivalent of a smoke detector’s test chirp. You know you’re supposed to care, but you don’t. It simply gets dismissed as annoying, tedious, and inconsequential, because it never proved necessary for day-to-day life to continue.
The thing is, though: that same instinct is the very thing we celebrate when it’s presented to us in a different way. Think of Erin Brockovich, poring over water district records no one asked her to examine. Hidden Figures, where women crunched the unglamorous numbers nobody else bothered to verify. Or The Six Triple Eight, sorting a backlog of mail no one deemed worth the effort, until it became the linchpin of morale. We’ll pay for a cinema ticket, or a streaming subscription, and spend two hours of our time to watch someone do the meticulous, unheralded work that went unrewarded in the moment. And it reminds us that the devil is in the detail, and the unexpected hero can actually be the unlikeliest person to become one. If they just had the stamina or the skillset to carry it through.
We just won’t do it ourselves, on a busy Tuesday, an hour before lunch, with that EULA popping up.
Half a Second
In March 2024, Microsoft engineer and PostgreSQL developer Andres Freund was running routine benchmarks on his home machine. Just another day of tinkering, doing routine work, when he noticed that logging in over SSH was taking about half a second longer than it should. Nothing seemed broken and no error messages popped up; it was just a bit slower. Half a second, imperceptibly to most. He could have dismissed it and, by his own admission, he nearly did. But instead, he went looking for that half second. What he uncovered was a backdoor, meticulously embedded into XZ Utils, an unassuming open-source compression library. It’s the kind of software only few may get excited about, but so foundational it’s easy to forget it exists. It is the invisible infrastructure that only becomes visible when it fails, which is why it made the perfect hiding spot.
The operation behind the backdoor had been years in the making. Someone using the alias Jia Tan had appeared in the project’s community, contributing useful code, earning trust with the overworked maintainer through consistency and patience. Other accounts emerged alongside Jia Tan, seemingly unrelated, pressing the maintainer to speed up development and grant Jia more access. Eventually, they did.
In February 2024, malicious code was slipped into two new versions of XZ Utils, disguised as harmless test data. Due to a chain of dependencies few had reason to question, this compression library sat directly upstream of SSHD, the software guarding remote access to countless Linux servers. Had the compromised versions been widely deployed, whoever held the corresponding key could have gained unauthorised, authentication-free access to a vast slice of the internet’s backbone.
Freund raised the alarm on March 29, 2024. The compromised versions were pulled within days. To this day, it’s unknown who Jia Tan is or who they worked for. What is known, is that the entire scheme unraveled because one person, doing something as mundane as benchmarking his own system, refused to ignore a half-second anomaly.
Which is to say that we’ve built a world where the most critical work is often the most invisible. Open-source maintainers, sysadmins, compliance officers; they’re the ‘immune system’ of our digital infrastructure, but they’re often regarded as background noise. The XZ Utils backdoor case however, is a cautionary tale about what can happen when we disregard or ignore the importance of our digital immune system.

Pulling it Off
There’s another tale that deserves attention; one that is not about a malicious actor pulling off their nefarious scheme. As it turns out, you don’t need a years-long infiltration campaign to break something this critical.
In March 2016, developer Azer Koçulu lost a trademark dispute over the name of one of his npm packages. In response, he unpublished all 272 of his packages, including one called left-pad. This 11-line utility that padded strings with extra characters seemed utterly trivial. But within minutes, builds across the JavaScript ecosystem began to fail. Thousands of projects, many unaware they even depended on left-pad (buried deep in dependency chains), stopped working. It took two and a half hours and a manual republish to restore full functionality.
No hacker. No state actor. No grand conspiracy.
The alarming bit about left-pad isn’t just that one person’s 11 lines of code could break thousands of projects. It’s that nobody knew. Modern software development relies on layers upon layers of dependencies, many of which are maintained by volunteers or underfunded teams. When Azer Koçulu pulled his packages, it exposed a truth we’d rather ignore: our digital ecosystem is built on a foundation of goodwill and trust.
In a nutshell, the argument is this: the custodians of the nitty-gritty, the unpaid maintainers, the overworked compliance officers, and the diligent journalists who actually read the annex, are doing work the rest of us have silently agreed isn’t worth noticing. Until the system grinds to a halt. XZ Utils shows what happens when bad actors exploit our blind spots; left-pad shows what happens when our blind spots lead to widespread system failure.
Eddy and the Industry
A few years ago, my friend Eddy Hagen and I called out a hardware manufacturer whose marketing claims didn’t hold up. To anyone with some industry expertise, it was clear how a story got spun around a failing business case. And where I and some others let go, Eddy kept researching and reporting because he refused to let the industry repeat something false simply because it was easier than verifying it. A similar story unfolded with another well-known hardware manufacturer: the marketing spin crumbled under scrutiny, yet the trade press largely seemed not to mind. Even if these examples aren’t dramatic enough to be made into movies, the disregard for detail eventually caused these companies to go bankrupt and buyers to lose a lot of money.
What these cases share with Freund’s half second isn’t technical genius. It’s knowing a field well enough to spot when something is slightly off, and then having the stubbornness to keep digging after everyone else has moved on. Eddy didn’t have a mandate or a stake in the case; he had expertise and, similar to Freund, the same refusal to dismiss what bugged him. That combination is rarer than it should be, and it’s rewarded far less often than the fleeting fame that follows after something goes wrong.

The Notice We Don’t Notice
What I find remarkable, is that these things happen all the time, everywhere. And we simply don’t seem to notice. Or we simply don’t care about what we sign up for.
Nissan’s privacy policy, for instance, has reportedly granted the company the right to collect data on customers’ psychological trends, behavior, intelligence, immigration status, and religious or philosophical beliefs. And all of it shareable with advertising partners. Kia’s policy has allegedly included sex life and sexual orientation in the small print; and also marked it as fair game for sharing. Shockingly, these aren’t even buried in obscure clauses; they’re public, sitting in the same category of documents nobody reads, right alongside the EULA’s we all click past.
If you think this is just an end-user’s mistake, think again. Around 2010–2011, a Capgemini-linked report allegedly found that Huawei had access to KPN’s Dutch mobile network broad enough to intercept calls. A network chosen by the government as their preferred mobile communication platform, and used by politicians. This information only surfaced publicly over a decade later. And as I write this, the Netherlands sits with a heated debate over the sale of Solvinity, the company managing critical infrastructure for DigiD (the Dutch national digital identity system), to USA-based technology company Kyndryl. The controversy only became a national conversation because whistleblower Pieter van Oordt refused to let it stay quiet.
Whistleblowers like Van Oordt don’t just risk their careers; they often sacrifice their peace of mind. The Solvinity-Kyndryl debate isn’t just about national security; rather, it’s about trust. When critical infrastructure changes hands with little public scrutiny, the burden of proof falls on those who do notice. And yet, we still treat whistleblowing as an act of defiance, rather than what it really is: a public service.
None of these are secrets, persé; they’re things that were technically disclosed, written down, filed, and then left for someone to notice. Just like XZ Utils’ compression library was left for someone to notice and the way left-pad held up half the internet without anyone checking.
We’ve trained ourselves to ignore the fine print, the footnotes, and the half-second delays, because the modern world rewards speed and convenience, not scrutiny and diligence. But what happens when the things that need our attention are the very things we’ve learned to overlook? The XZ Utils backdoor, Nissan’s privacy policy, the Solvinity sale; they’re all symptoms of the same disease: a society that has confused visibility with importance.
The Boring Truth
I don’t think the answer is a training course on reading EULA’s, nor is it more compliance theater. What Freund did, what Eddy did (and still does today), what a handful of exhausted maintainers and a Dutch whistleblower did, wasn’t about following procedure; it was a refusal to accept “it’s probably fine” as a complete answer.
We already know how to celebrate that instinct after the fact: we give it a film adaptation, an award, and a headline. What we’ve stopped doing is paying it any attention and giving it any credits while it’s still boring. But the truth is that we need the one person staring a little too long at something the rest of us decided wasn’t worth the half second.

Comments are closed