Search
Items tagged with: xz
Who in the world is Jia Tan?
https://boehs.org/node/everything-i-know-about-the-xz-backdoor
https://rheaeve.substack.com/p/xz-backdoor-times-damned-times-and
https://lcamtuf.substack.com/p/technologist-vs-spy-the-xz-backdoor
From China? Eastern Europe? Nice graphic from twitter.
Techies vs spies: the xz backdoor debate
Diving into some of the dynamics and the interpretations of the brazen ploy to subvert the liblzma compression library.lcamtuf (lcamtuf’s thing)
The #xz vulnerability really has me feeling good about not living on the bleeding edge. I'm sure there's still some risk of a terrible backdoor somewhere in Debian or Ubuntu that hasn't been found yet, but at least there's a much higher chance of someone catching it before it bites me.
Only thing of mine that was affected was my Termux installations on my Android devices, something I never use for SSH anyway.
A pretty interesting article loosely related to the #xz mess and it's cleanup process.
Reproducible builds, verifiable build chains. Lot of good stuff.
So now that we all understand that thanklessly relying on free work of overworked maintainers is a problem, how about we put our money where our mouth is?
I think @AndresFreundTec needs a fat bonus check for saving our asses.
And Lasse Collin needs a lot of support, and probably a nice vacation.
I pledge $100, for starters.
Now how can we make sure to send the funds to the correct people?
Or is there already any fundraiser that I missed?
„GitHub Disables The XZ Repository Following Today's Malicious Disclosure“
https://www.phoronix.com/news/GitHub-Disables-XZ-Repo
GitHub Disables The XZ Repository Following Today's Malicious Disclosure
Today's disclosure of XZ upstream release packages containing malicious code to compromise remote SSH access has certainly been an Easter weekend surprise..www.phoronix.com
Is there concern for snaps or flatpaks? Checking my own stuff it looks like applications using bundled liblzma are running in the 5.2.* - 5.4.* versions, but if someone has a bleeding edge application running an affected version, what would the remediation be? Would uninstalling it be sufficient?
Eek. Apparently liblzma (part of the xz package) has a backdoor in versions 5.6.0 and 5.6.1, causing SSH to be compromised.
https://www.openwall.com/lists/oss-security/2024/03/29/4
This might even have been done on purpose by the upstream devs.
Developing story, please take with a grain of salt.
The 5.6 versions are somewhat recent, depending on how bleeding edge your distro is you might not be affected.