Adrian Mastronardi has published a free book titled Half a Second that reconstructs the 2024 XZ backdoor incident as a continuous narrative. The book is available under a Creative Commons noncommercial, no-derivatives license and traces how a single engineer's momentary curiosity unraveled what could have become one of the most devastating supply chain attacks in open-source history.
The Story the Book Tells
Mastronardi frames the incident around three central figures: a burned-out volunteer maintainer who was gradually manipulated into surrendering control of the XZ Utils project, the engineer who spotted the anomaly, and the still-unidentified attacker who built the backdoor. The book argues that the operator behind the attack may never be found, a sobering reminder of how anonymous modern cyber threats can remain even after exposure.
The narrative approach is deliberate. Rather than presenting a dry technical post-mortem, Mastronardi writes the story as a thriller, emphasizing the human decisions and vulnerabilities that allowed the backdoor to persist for weeks before discovery.
A Divided Reception
Reactions from the Linux and open-source community have been mixed. Some readers praised the book's thorough research and accessibility for non-technical audiences. One commenter compared it favorably to Steven Levy's Hackers, noting that it avoids the tangential digressions that plague some technology histories.
Others found the prose overwrought. Multiple readers described the writing as "flowery" and "sensationalist," with one critic noting that early chapters felt like they had been run through a tool instructed to "make this wordier." The repetitive stylistic tics, including heavy use of phrases like "it is worth marking" and architectural metaphors such as "seam" and "spine," led some to suspect the author used AI assistance to polish the manuscript.
The AI Writing Debate
The question of whether AI tools shaped the book has become a story in itself. One reader ran passages through Claude and received a verdict of "human-owned research, argument and sourcing; model-smoothed prose." Another commenter pointed to specific sentences as evidence of "Claudespeak," arguing that the polished English from a writer whose first language is Spanish raised flags.
That observation drew pushback. Critics called it a thinly veiled slight against non-native speakers, arguing that fluency should not be treated as evidence of machine generation. The broader debate touches on an uncomfortable reality: as AI writing tools improve, distinguishing between human and machine prose is becoming harder, and the criteria we use to make that judgment often reveal our own biases.
Technical Alternatives Already Exist
For readers seeking a more concise, technical treatment, community members have pointed to Russ Cox's detailed analysis of the backdoor, which strips away narrative flourish in favor of code-level specificity. Cox's work remains the go-to reference for engineers who need to understand exactly how the payload functioned and how it was detected.
Mastronardi's book, by contrast, aims for a wider audience. It is a bet that the general public, not just specialists, needs to understand how fragile the infrastructure of modern computing really is. That ambition is commendable, even if the execution is contentious.
What This Means for Open Source
The XZ backdoor was a watershed moment because it exposed how much critical software relies on unpaid, often isolated maintainers. The social engineering that preceded the technical attack, the patient grooming of a volunteer over months, is arguably the scarier part of the story. No amount of automated scanning can fully defend against a determined adversary who invests in understanding human weakness.
Mastronardi's book, whatever its stylistic flaws, keeps that lesson in focus. As the open-source community continues to grapple with sustainability and security, the human dimension of this attack deserves the attention it gets here. Whether the prose is too polished or not polished enough, the underlying facts remain urgent.
Watch for whether the book's publication prompts broader discussions about AI disclosure in nonfiction writing, and whether the still-missing attacker ever resurfaces in future investigations.