On 28 August 2011, developers at kernel.org realized that there had been a major security breach. Intruders had gained root access to the system and added a trojan to the startup scripts. Developers reinstalled all the servers and investigated the origin of the attack.5 It is likely, although not confirmed, that the kernel.org intrusion is related to the intrusions of LinuxFoundation.org and Linux.com websites that were determined shortly afterwards.67
Git, a distributed and open-source source management system designed by Linus Torvalds to guarantee the integrity of the source code, is used to keep track of changes in the Linux source code. This and the fact that the source code is available to anyone and widely known makes any attempt to tamper with the source code fairly easy to detect and revert if required.8 All that makes kernel.org not the primary repository, but rather a distribution point of the kernel sources.
Kernel.org was back online by November 2011, with the exception of a few secondary services.9 A 27 year old resident of Florida, US was arrested in 2016 for the attack.10
"The Linux Kernel Organization". Kernel.org. Linux Kernel Organization. 2013-12-05. Retrieved 2015-01-15. https://www.kernel.org/category/about.html ↩
"The Linux Kernel Archives - FAQ". Kernel.org. Linux Kernel Organization. 2014-09-02. Retrieved 2015-01-16. https://www.kernel.org/category/faq.html ↩
"Mirrors.kernel.org, a service of the Linux Kernel Archives". Kernel.org. Linux Kernel Organization. 2014-12-13. Retrieved 2015-01-16. https://mirrors.kernel.org/ ↩
Konstantin Ryabitsev (2014-08-18). "Linux Kernel Git Repositories Add 2-Factor Authentication". Linux.com. Archived from the original on 2018-01-31. Retrieved 2014-08-22. https://web.archive.org/web/20180131082600/https://www.linuxfoundation.org/blog/linux-kernel-git-repositories-add-2-factor-authentication/ ↩
Jonathan Corbet (2011-08-31). "The cracking of kernel.org". The Linux Foundation. Archived from the original on 2011-10-29. Retrieved 2011-11-08. https://web.archive.org/web/20111029105944/http://www.linuxfoundation.org/news-media/blogs/browse/2011/08/cracking-kernelorg ↩
"Blog Archive » kernel.org down for maintenance?". Heimic. 2011-09-13. Archived from the original on 2011-09-23. Retrieved 2014-03-02. https://web.archive.org/web/20110923203507/http://www.heimic.net/2011/09/13/kernel-org-down-for-maintenance/ ↩
"kernel.org is down!". 16 September 2011. https://mycottonsilk.wordpress.com/2011/09/16/kernel-org-is-down/ ↩
Fahmida Y. Rashid (2011-09-01). "Kernel.org hacked, but Linux kernel safe thanks to git". linuxfordevices.com. Archived from the original on 2013-01-27. Retrieved 2011-11-08. https://archive.today/20130127213718/http://www.linuxfordevices.com/c/a/News/Kernelorg-hacked/ ↩
Dan Goodin (2013-09-24). "Who rooted kernel.org servers two years ago, how did it happen, and why?". Ars Technica. Retrieved 2018-01-30. https://arstechnica.com/information-technology/2013/09/who-rooted-kernel-org-servers-two-years-ago-how-did-it-happen-and-why/ ↩
"Feds pin brazen kernel.org intrusion on 27-year-old programmer". Ars Technica. https://arstechnica.com/tech-policy/2016/09/feds-pin-brazen-kernel-org-intrusion-on-27-year-old-programmer/ ↩