Who in the world is Jia Tan?
https://boehs.org/node/everything-i-know-about-the-xz-backdoor
https://rheaeve.substack.com/p/xz-backdoor-times-damned-times-and
https://lcamtuf.substack.com/p/technologist-vs-spy-the-xz-backdoor
From China? Eastern Europe? Nice graphic from twitter.
Techies vs spies: the xz backdoor debate
Diving into some of the dynamics and the interpretations of the brazen ploy to subvert the liblzma compression library.lcamtuf (lcamtuf’s thing)
like this
N. E. Felibata 👽 reshared this.
gunnar
•https://gist.github.com/thesamesam/223949d5a074ebc3dce9ee78baad9e27
^FAQ on the xz-utils backdoor (CVE-2024-3094)
xz-utils backdoor situation (CVE-2024-3094)
Gistgunnar
•There is a remarkable comment here:
https://gynvael.coldwind.pl/?lang=en&id=782
"I can't stop thinking this is a spy agency job. I mean hackers will try to have quick return on investment, while here it is like it does not matter.
This remind me of such spyware #pegasus that use unknown security breach to provide spy service for governmental agencies."
xz/liblzma: Bash-stage Obfuscation Explained
gynvael.coldwind.plgunnar
•Good timeline summary:
https://research.swtch.com/xz-timeline
research!rsc: Timeline of the xz open source attack
research.swtch.com