

I think in the future, it is advisable to use larger distributions where a lot of eyes look at, like Debian.
This reminds me of the time when Debian broke their OpenSSL and for two years, ssh keys generated on Debian were basically taken from a pool of only 32k different keys…
That time it was an honest mistake, but it would actually have been a very efficient attack too if it had been intentional. Imagine succeeding at getting your target to use private keys for ssh or ssl etc. from a tiny pool that makes something usually impossible to brute force suddenly trivial. And nobody noticed it for two years.
He’s not from Russia though. He was born in Uzbekistan and he was 5 when the Soviet Union collapsed. He grew up in Malta and in the US.