sos, to foss
@sos@mastodon.gamedev.place avatar

Hey I need to get LZMA/LZMA2 lib source, where do I get one that's untouched by the scam person?

marcel, to random German
@marcel@waldvogel.family avatar

Wir sind dieses Wochenende nur durch unglaubliches Glück und extrem knapp an wohl einer der grössten Katastrophen rund um die globale IT-Sicherheit vorbeigeschrammt.

Phuh! Doch — was ist eigentlich passiert? Wie konnte das überhaupt geschehen? Und was können (und müssen) wir tun, um dies zukünftig zu vermeiden?

Und: Danke an die ganzen IT-Helden, die dies an diesem langen Wochenende für uns getan haben.

https://dnip.ch/2024/04/02/xz-open-source-ostern-welt-retten/

marcel,
@marcel@waldvogel.family avatar

Der Angriff hatte zum Ziel, Abermillionen von Servern weltweit für die unbekannten Angreifer zu öffnen. Was diese mit den Früchten der Vorbereitung der letzten 3 Jahre dann hätten erreichen wollen, das werden wir wohl nie erfahren. Aber die potenziellen Auswirkungen auf Abermillionen von Nutzerinnen, ihren Daten aber auch die Wirtschaft und Stabilität von ganzen Ländern hätten dramatisch werden können.

https://dnip.ch/2024/04/02/xz-open-source-ostern-welt-retten/

marcel,
@marcel@waldvogel.family avatar

Durch Good-Cop/Bad-Cop-Taktiken wurden Softwareentwickler dazu gedrängt, subtil versteckte Sicherheitslücken einzubauen. Wie können wir das zukünftig vermeiden?
.
1️⃣ Vereinfachung/Reduzierung von Programmen und Abhängigkeiten
2️⃣ Mehr Wertschätzung und Unterstützung für die Open-Source-Entwickler
3️⃣ Bessere Kontrolle, aber ohne Belastung für die Entwickler
4️⃣ Angewandtere Ausbildung

Was sind eure Ideen dazu? Freue mich auf Feedback!


https://marcel-waldvogel.ch/2024/04/02/wie-die-open-source-community-an-ostern-die-it-welt-rettete/

marcel,
@marcel@waldvogel.family avatar

«Die Feiertage. Die ganzen IT-Abteilungen feiern mit der Familie… Die ganzen IT-Abteilungen? Nein! Eine von unbeugsamen Open-Source-Enthusiasten bevölkerte Mailingliste hört nicht auf, den Eindringlingen Widerstand zu leisten.»


https://dnip.ch/2024/04/02/xz-open-source-ostern-welt-retten/

isaac, to linux
@isaac@hachyderm.io avatar

what's really wild is that I bet state actors could just find and offer money to unscrupulous open source contributors instead of wasting years on infiltration.

I bet somebody like that has his DMs open right now and state actors just have to be brave enough to reach out.

heck, state actors, I bet the answer is right in front of your eye sacks.

to repeat, the ANSWER is in front of your EYE SACK...

#getfedihired #liblzma #lzma #xz #cve #linux #OpenSSH

veronica, to python
@veronica@mastodon.online avatar
stdevel, to linux
@stdevel@chaos.social avatar

Admins on Monday be like…

morph, to random German
@morph@chaos.social avatar

Finde die -/ -Backdoor braucht noch nen catchy Namen, sonst wird das alles nix… Vorschläge bitte hier drunter! 👇

  • lzmARSCH
  • xzIBIT
  • SSHeartbreak

🤔

uncanny_static, to openSUSE
@uncanny_static@chaos.social avatar

Unfortunately, openSUSE Tumbleweed already includes version 5.6.1 of liblzma. Hence, if you are using Tumbleweed, your system might already be affected.
https://www.openwall.com/lists/oss-security/2024/03/29/4

uncanny_static,
@uncanny_static@chaos.social avatar

OpenSSH in openSUSE also seems to be patched to link to libsystemd, thus linking to liblzma. Hence, Tumbleweed should be affected. 😔

scy, to random
@scy@chaos.social avatar

Eek. Apparently liblzma (part of the xz package) has a backdoor in versions 5.6.0 and 5.6.1, causing SSH to be compromised.

https://www.openwall.com/lists/oss-security/2024/03/29/4

This might even have been done on purpose by the upstream devs.

Developing story, please take with a grain of salt.

The 5.6 versions are somewhat recent, depending on how bleeding edge your distro is you might not be affected.

kkarhan, to linux
@kkarhan@mstdn.social avatar

I really did underestimate as compression for a :

I was able to just shove the pre-made, full & uncut binary from @landley and still have some breathing room.

Tho I expect this to change once I put a in that has actual capabilities...

This will be interesting for OS/1337.

http://landley.net/toybox/bin/
https://landley.net/toybox/help.html

the complete toybox binary outputting the commands it has implemented

kkarhan,
@kkarhan@mstdn.social avatar

@lupo the problem is that i already compress the hell out of stuff:
I literally chose over and for both ans to get both as small as possible...

OFC I'll gladly accept any help in that way...
https://github.com/OS-1337/OS1337

And yes, the similarity to and is not an accident but desired:
https://github.com/OS-1337/OS1337/blob/main/docu/acknowledgements.md#notable-mentions

jupiter, to amateurradio

Tired: Morse code was the first digital mode
Wired: Morse code was the first variable length encoding

kkarhan,
@kkarhan@mstdn.social avatar

@vk6flab @jupiter for the condition of "static lossless " the bar is extremely low.

OFC it won't be even remotely efficient when compared to modern compression...
Even will run circles around it, not to mention , or high-efficiency vocoders like ....

https://mstdn.social/@kkarhan/110692504545982742

mike, to TodayILearned
@mike@jammer.social avatar

Today I learned: Linux has multiple cats. 😺

For every single file compressor: , , , , and , there is a matching cat command: zcat, bzcat, lzcat, xzcat, and zstdcat.

Demonstrating that each cat command (zcat, bzcat, lzcat, xzcat, and zstdcat) produces the same output: "Hello World!"

  • All
  • Subscribed
  • Moderated
  • Favorites
  • JUstTest
  • cisconetworking
  • DreamBathrooms
  • InstantRegret
  • mdbf
  • khanakhh
  • magazineikmin
  • Durango
  • Youngstown
  • slotface
  • rosin
  • everett
  • kavyap
  • Leos
  • megavids
  • ngwrru68w68
  • tacticalgear
  • osvaldo12
  • GTA5RPClips
  • ethstaker
  • thenastyranch
  • cubers
  • anitta
  • tester
  • modclub
  • normalnudes
  • provamag3
  • lostlight
  • All magazines