Pantherina

@Pantherina@feddit.de

This profile is from a federated server and may be incomplete. Browse more on the original instance.

Best article about XZ backdoor?

Hey, I’ve been hearing a LOT about the xz backdoor. Crazy story, but rather than reading 10 different articles about it from 3 days ago when the story was quite new, does anybody know a high quality write-up that has all the juicy details and facts? I really like in-depth guides that cover every aspect of the story....

Pantherina,

Yes the data was lost on Windows, but I prefer Linux a lot as all good tools seem to be linux only anyways haha. But will remember recuva as a last option.

Also no the disk is not booted anymore.

Pantherina,

The files are deleted as that folder was too big

Pantherina,

The files are deleted as that folder was too big

Pantherina,

The small drive is nearly empty, just has a few files, those where deleted. The drive is now unuses, used testdisk, photorec, recuva now scalpel to get anything from it.

The files are there, for sure.

Pantherina, (edited )

Cannabinoide und Terpene sind fettlöslich. Am effektivsten ist es aber, nicht Fett zu nehmen, sondern ein Lösungsmittel wie Isopropanol. Das ist nicht trinkbar aber nicht vergällt wie Ethanol (Alkohol) und von daher 99,999% rein und billig.

Also kleinmachen, in Propanol liegen lassen für paar Tage, durch einen Kaffefilter Abkippen in Öl deiner Wahl, und dann zusammen unter Rühren das Propanol verdampfen lassen bei bis zu 100°C.

Das ganze kann man dann nochmal wiederholen, und man hat sicher das meiste extrahiert.

kde, to kde
@kde@floss.social avatar

We write all recipes for our juiciest empanadas in our notebooks. Version 1.1.0 available now!

https://carlschwan.eu/2024/04/01/marknote-1.1.0/

Flatpak coming today!

@kde

Pantherina,

Awesome

Pantherina,

They didnt use Pipewire before??

Pantherina,

Lolz

fedoraproject.org/wiki/Changes/DefaultPipeWire

I know that Fedora does breaking changes and basically beta tests, but Pipewire “just works” since at least 2 years

Pantherina,

This. Androids permission toggles combine multiple ones. GrapheneOS actually adds more of these toggles, as some things like Network and various sensor permissions are always on (wtf Android). But even those are combined toggles.

You can also display more permissions on the permission page, top right.

Will antivirus be more significant on Linux desktop after this xz-util backdoor?

I understand that no Operating System is 100% safe. Although this backdoor is likely only affects certain Linux desktop users, particularly those running unstable Debian or testing builds of Fedora (like versions 40 or 41), **Could this be a sign that antivirus software should be more widely used on Linux desktops? ** ( I know...

Pantherina,

Your distro should absolutely include that. And make sure to actually close all not needed ports, which is more work but the GUIs allow that easily.

Pantherina,

Fedora does

Pantherina,

Okay thats crazy. Maybe RPM installs can losen the firewall, or maybe common things are always open.

Pantherina, (edited )

Okeeee aber was hälst du davon?

https://feddit.de/pictrs/image/fdfe79f8-cd84-481a-a710-7be30b6f77a8.jpeg

  • sau dumm
  • aus nicht haltbarem Speckstein
  • sau schwer
  • wird auch mit nem Propanfeuerzeug betrieben
  • keine Ahnung wann man fertig gedampft hat (aber bleibt kühl und verbrennt nicht)
  • braucht ne Ablage wenn sie heiß wird
  • sieht kühl aus
  • schmeckt nach Holz

(erstellt mit unfreier Software “Gridart” die am wenigsten müllig ist, keine einzige unterstützt das share-portal oder foto-portal)

Pantherina,

Ist eine Verdampferpfeife ;D punkt 6

Glühbirnen haben manchmal quecksilber drin oder sowas, um eventuelles UV licht in sichtbares Licht umzuwandeln.

Pantherina,

Du hast Kreck vergessen, die Kiffer die müssen ja jetzt ausweichen weil jetzt alle immer umsonst in Kindergärten kiffen können und nix mehr merken!

Pantherina,

That scentence makes little sense as both are using package managers that work similarly. Flatpak even uses ostree which is more advanced.

Pantherina,

I should do a “sorting DEs by their taste” meme

Pantherina,

Cough Fedora does that (using rpm-sequoia written in Rust) and also uses zst instead of xz for RPMs since Fedora 31

Pantherina,

True. But please dont be harassing anyways

Pantherina,

We dont live in such a perfect world. Linux has a small marketshare for non-server software, so packaging is done by your distro.

You would need to have user-facing settings for Apparmor or SELinux to replicate what already exists with Flatpak.

Principle of least privilege.

Maybe you prefer native packages, but bubblejail or SELinux confined users are complicated as hell and both are pre-alpha in my experience.

So yes you add bloat, dependencies etc. But you also add stability, a small core system, take load of OS developers and unify the packaging efforts so that it is done by developers not packagers.

This reduces complexity a lot, as the underlying system is not as important anymore, and you can just use whatever you want. Software is separated from the OS.

Flatpak is the only good format, as explained in this talk

(Snap has no sandboxing outside of Ubuntu and is thus not portable, Appimages are inherently insecure)

Pantherina,

Oh nice, its from their repo not f-droid

Pantherina,

No KDE settings are all done in the homedir, there is nothing snapshotted here

bugs.kde.org/show_bug.cgi?id=240862

Pantherina,

Edit: EndlessOS is the immutable Debian distro, not ElementaryOS.

  • All
  • Subscribed
  • Moderated
  • Favorites
  • Leos
  • everett
  • magazineikmin
  • thenastyranch
  • Youngstown
  • vwfavf
  • rosin
  • slotface
  • khanakhh
  • InstantRegret
  • PowerRangers
  • kavyap
  • tsrsr
  • DreamBathrooms
  • normalnudes
  • mdbf
  • hgfsjryuu7
  • tacticalgear
  • ethstaker
  • osvaldo12
  • ngwrru68w68
  • GTA5RPClips
  • Durango
  • modclub
  • cisconetworking
  • cubers
  • tester
  • anitta
  • All magazines