New Book 'Half a Second' Revisits XZ Utils Backdoor
20 Jul 2026
A Half-Second Delay That Exposed a Two-Year Attack
A new book titled Half a Second, written by Adrian Mastronardi, is bringing renewed attention to one of the more unsettling open-source security incidents in recent memory: the XZ Utils backdoor.
According to the report, the story centers on a single moment — March 29, 2024 — when a Microsoft engineer noticed that logging into a test machine was taking about half a second longer than expected. That small anomaly triggered an investigation that ultimately uncovered a backdoor embedded in XZ Utils, a compression utility present on nearly every Linux system on Earth, including servers that carry much of the internet's traffic.
Per the report, someone had spent two years building this backdoor before it was caught. The book is described as "interpretive narrative nonfiction, written for the general reader" that "assumes no technical background," suggesting an effort to make the incident accessible beyond security specialists. Its copyright is dated 2026, though the report does not clarify whether this reflects a planned publication date. The book's companion website is licensed under CC BY-NC-ND 4.0 and, per its stated terms, will always be free.
What We Still Don't Know
The report flags several open questions the available material doesn't answer: who built the backdoor and why, who is publishing the book and when it will be released, exactly how the half-second delay led investigators to the backdoor's code, and how many systems or organizations were affected before discovery. The gap between the 2024 incident and the 2026 copyright date also remains unexplained.
Why Founders Should Care
This story is likely to resonate with founders building on open-source infrastructure, for a few reasons:
- Supply-chain exposure is broad by default. XZ Utils' near-universal presence across Linux systems suggests that widely used open-source components can carry substantial, hard-to-see attack surface — a risk that may extend to other foundational dependencies startups rely on daily.
- Patience is a viable attack strategy. A two-year effort to embed this backdoor indicates that similarly long, quiet campaigns against other open-source projects are plausible. Founders may want to treat dependency security as an ongoing process rather than a one-time audit.
- Small signals can matter. The entire discovery hinged on a half-second login delay. Teams that build in anomaly detection — even for seemingly minor performance shifts — may be better positioned to catch issues that automated scanning misses.
- Public attention could shift market demand. A mainstream, non-technical book on this topic may raise broader awareness of software supply-chain risk among investors, customers, and partners — potentially increasing interest in security tooling and open-source auditing services.
The Bigger Picture
For early-stage teams, the underlying lesson isn't really about XZ Utils specifically — it's about the assumptions embedded in modern software stacks. Nearly every startup depends on open-source components maintained by small teams or individuals, often without dedicated security review. This incident is a reminder that dependency provenance, maintainer vetting, and long-term monitoring are worth budgeting for, even at the earliest stages, since the cost of catching a backdoor early is far lower than the cost of discovering one two years in.