1 point

Don’t forget all of this was discovered because ssh was running 0.5 seconds slower

permalink
report
reply
0 points

Postgres sort of saved the day

permalink
report
parent
reply
0 points

RIP Simon Riggs

permalink
report
parent
reply
0 points

I have been reading about this since the news broke and still can’t fully wrap my head around how it works. What an impressive level of sophistication.

permalink
report
reply
0 points
*

And due to open source, it was still caught within a month. Nothing could ever convince me more than that how secure FOSS can be.

permalink
report
parent
reply
0 points

Idk if that’s the right takeaway, more like ‘oh shit there’s probably many of these long con contributors out there, and we just happened to catch this one because it was a little sloppy due to the 0.5s thing’

This shit got merged. Binary blobs and hex digit replacements. Into low level code that many things use. Just imagine how often there’s no oversight at all

permalink
report
parent
reply
0 points

Any additional information been found on the user?

permalink
report
reply
0 points
*

as long as you’re up to date on everything here: https://boehs.org/node/everything-i-know-about-the-xz-backdoor

the only additional thing i’ve seen noted is a possibilty that they were using Arch based on investigation of the tarball that they provided to distro maintainers

permalink
report
parent
reply
0 points

The tukaani github repos are gone, is there a mirror somewhere?

permalink
report
reply
0 points

Tukaani main website

permalink
report
parent
reply
0 points
*

Though unfortunately (or I guess for most use-cases fortunately) you can’t find the malicious m4/build-to-host.m4 file on there afaik. The best way to find that now, should you really want to, is by looking through the commit history of the salsa.debian.org/debian/xz-utils repository which is, as far as I understand it, the repository that the debian packages are built from and consequently also what the compromised packages were built from.

permalink
report
parent
reply
0 points

In a nutshell you say…

permalink
report
reply
0 points

Coconut at least…

permalink
report
parent
reply

Linux

!linux@lemmy.ml

Create post

From Wikipedia, the free encyclopedia

Linux is a family of open source Unix-like operating systems based on the Linux kernel, an operating system kernel first released on September 17, 1991 by Linus Torvalds. Linux is typically packaged in a Linux distribution (or distro for short).

Distributions include the Linux kernel and supporting system software and libraries, many of which are provided by the GNU Project. Many Linux distributions use the word “Linux” in their name, but the Free Software Foundation uses the name GNU/Linux to emphasize the importance of GNU software, causing some controversy.

Rules

  • Posts must be relevant to operating systems running the Linux kernel. GNU/Linux or otherwise.
  • No misinformation
  • No NSFW content
  • No hate speech, bigotry, etc

Related Communities

Community icon by Alpár-Etele Méder, licensed under CC BY 3.0

Community stats

  • 9.3K

    Monthly active users

  • 3.2K

    Posts

  • 37K

    Comments