echo_pbreyer, to random German
@echo_pbreyer@digitalcourage.social avatar

🇬🇧 attack: Unknown persons attempted to install a global, highly dangerous backdoor in IT systems.

Beware: The 🇪🇺 Commission is planning "legal" backdoors for devices & apps! PR-speak: /
https://home-affairs.ec.europa.eu/document/download/17739cd7-098e-4df3-8f41-37be73560086_en?filename=HLG-WG1-background-document-05122023_en.pdf @GreensEFA
More:

nemobis,
@nemobis@mamot.fr avatar

@echo_pbreyer Next self-defense: "I was merely preparing everyone's systems for EU regulatory compliance!".

xtaran, to debian
@xtaran@chaos.social avatar

Yay, reduces dependencies (in Debian Unstable for now) and removes dependency.

openssh (1:9.7p1-4) unstable; urgency=medium

  • Rework systemd readiness notification and socket activation patches to not link against libsystemd (the former via an upstream patch).
  • […]

Thanks Colin Watson!

(via https://tracker.debian.org/news/1516548/accepted-openssh-197p1-4-source-into-unstable/)

vitali64sur, to random
@vitali64sur@mamot.fr avatar

Woah, that xz backdoor is nasty.

Thanks for nothing I guess. :P

Aaron, to random German
@Aaron@troet.cafe avatar

The original maintainer of (Lasse) just fixed another affected piece of code that sabotaged library sandboxing and was, of course, also introduced by the malicious contributor Jia Tan.

https://git.tukaani.org/?p=xz.git;a=summary

This poor unpaid Fossdev probably has a ton of companies knocking on his door right now.

xtaran,
@xtaran@chaos.social avatar

@Aaron: Oh, and the now infamous "Simplify SECURITY.md" commit by is now also in that repo: https://git.tukaani.org/?p=xz.git;a=commit;h=af071ef7702debef4f1d324616a0137a5001c14c

So it's up to date with Github again (and now ahead of it).

simon, to random
@simon@fosstodon.org avatar
mirabilos, to random DE
@mirabilos@toot.mirbsd.org avatar

I was considering replying to this comment on the “please update xz package” bugreport earlier with that the discussion is not irrelevant and that it’s the maintainer’s responsibility on new upgrades to check for new legal issues and “other hidden gems”.

I didn’t because I didn’t want to bother going in with an annoyed self-righteous “user”.

Now it turns out all three of the involved ones were “string + number @ freemailer” sockpuppets, so it’s probably okay I didn’t bother.

Not that I blame Sebastian — it was very well hidden, and even my usual diffing between old and new version would not have found it.

I do take away from this to also check the diff between VCS repo at the time of the release and release tarball. Perhaps also between branch and tag if they, like Apache Tomcat, introduce extra commits there.

karma, to random Polish
@karma@101010.pl avatar

🧵 1/6

Szybka historyjka, co działo się w ciągu ostatnich kilkunastu godzin (czy raczej kilkunastu miesięcy?) w świecie open-source.

Istnieje sobie otwartoźródłowy projekt o nazwie “xz” autorstwa Lasse Collin[1].
Od około dwóch lat jednym ze współtwórców tego projektu jest użytkownik o pseudonimie “JiaT75”[2].

karma,
@karma@101010.pl avatar
mjg59, to random
@mjg59@nondeterministic.computer avatar

Just finished writing my lengthy paper on how "Many eyes make all bugs shallow", time to check what's happening on the internet today

der_istvan,
@der_istvan@chaos.social avatar

@mjg59 Oh boy...

  • All
  • Subscribed
  • Moderated
  • Favorites
  • provamag3
  • kavyap
  • DreamBathrooms
  • InstantRegret
  • magazineikmin
  • ngwrru68w68
  • Durango
  • thenastyranch
  • Youngstown
  • rosin
  • slotface
  • tacticalgear
  • mdbf
  • ethstaker
  • JUstTest
  • khanakhh
  • osvaldo12
  • GTA5RPClips
  • cubers
  • cisconetworking
  • everett
  • tester
  • modclub
  • megavids
  • Leos
  • normalnudes
  • anitta
  • lostlight
  • All magazines