[a / b / c / d / e / f / g / gif / h / hr / k / m / o / p / s / t / u / v / vg / vm / vmg / vr / vrpg / vst / w / wg] [i / ic] [r9k / s4s / vip] [cm / hm / lgbt / y] [3 / aco / adv / an / bant / biz / cgl / ck / co / diy / fa / fit / gd / hc / his / int / jp / lit / mlp / mu / n / news / out / po / pol / pw / qst / sci / soc / sp / tg / toy / trv / tv / vp / vt / wsg / wsr / x / xs] [Settings] [Search] [Mobile] [Home]
Board
Settings Mobile Home
/g/ - Technology


Thread archived.
You cannot reply anymore.


[Advertise on 4chan]


File: xz_utils.png (34 KB, 266x216)
34 KB PNG
>start contributing code fixes to multiple open-source projects
>raise issues on GitHub for problems
>work yourself up the food chain
>use sock puppets to complain about the author of a major project
>become an appointed maintainer of that project
>start inserting malicious code
And all it took was a single autist being triggered by ssh sessions starting a fraction of a second slower than normal to be caught. Over 2 years of work down the drain. But this raises a question: is this happening right now on other projects with other people?
>>
Has anyone ever figured out who this was and who he was affiliated with by the way?
>The IRC channel #tukaani on Libera Chat has been a little more active recently. :-)
>https://www.mail-archive.com/xz-devel@tukaani.org/msg00634.html
>>
half-second.com has some sort of book on this, haven't read it yet but there you go
>>
File: 0_I51AKRrTtjBn4rmY.png (572 KB, 725x544)
572 KB PNG
>>109401296
You should always assume that is the case. That said one trick to mimize the risk is to reduce standardization: the less widespread the surface of the attack the less convenient the investment in preparing such attack vectors, example in case the xz bug only affected systems where liblzma linked to openssh, if you were to use a less centralized solution (or even better not using systemd cancer to begin with) you would be also unaffected.
One of the original strengths of linux security was its "fragmented" nature other than being subject of constant scrutiny.
>>
>>109401296
>is this happening right now on other projects with other people?
yes. There are tons of people trying similar on other projects. It's pretty fucking obvious and was already said enough times before that
>>
>>109401296
it was random nobody that uploaded the malicious compiled binary
it wasn't malicious code iirc
>>
>>109401296
Thanks to MicroSlop, xz is not stealing our dick pics.
Based MicroJeet
>>
>>109401478
>Release early, Release often
So big tech are the good guys?



[Advertise on 4chan]

Delete Post: [File Only] Style:
[Disable Mobile View / Use Desktop Site]

[Enable Mobile View / Use Mobile Site]

All trademarks and copyrights on this page are owned by their respective parties. Images uploaded are the responsibility of the Poster. Comments are owned by the Poster.