xtaran, to debian
@xtaran@chaos.social avatar

Yay, reduces dependencies (in Debian Unstable for now) and removes dependency.

openssh (1:9.7p1-4) unstable; urgency=medium

  • Rework systemd readiness notification and socket activation patches to not link against libsystemd (the former via an upstream patch).
  • […]

Thanks Colin Watson!

(via https://tracker.debian.org/news/1516548/accepted-openssh-197p1-4-source-into-unstable/)

Conan_Kudo, to random
@Conan_Kudo@fosstodon.org avatar

All this talk about over the weekend, I want to also point out that it's important to remember that the "software supply chain" largely does not exist in regards to open source, because most people have no real relationship other than parasitic consumption with the project.

@Di4na's great blog post on this topic explains it quite well: https://www.softwaremaxims.com/blog/not-a-supplier

shellsharks, to infosec
@shellsharks@shellsharks.social avatar

There's A LOT going on (analysis, discussion, vendor notices, etc...) related to the ongoing xz/liblzma compromise so I created a "link roundup" which centralizes and buckets a lot of the awesome links and threads I've seen flying around.

https://shellsharks.com/xz-compromise-link-roundup

I will try to keep this up-to-date (ish) for a few days while things are hot but I make no promises beyond that.

jwf, to linux
@jwf@floss.social avatar

Most of my feed on the mess is solution-eering on ideas for paying maintainers. It implies the way to fix this is to simply pay people for their time.

I am not seeing something else though. Has anyone actually asked the maintainer what they want? What if that answer was not money? What if it was "I don't want to do this anymore?"

Regardless of the answer this time around, we should be prepared to boldly face these types of answers too.

mkb, to infosec
@mkb@mastodon.social avatar

OK, peeps, what’s the over/under on the number of days before another vuln with the same M.O. as is found?

And what about attribution? Place your bets!

Aaron, to random German
@Aaron@troet.cafe avatar

The original maintainer of (Lasse) just fixed another affected piece of code that sabotaged library sandboxing and was, of course, also introduced by the malicious contributor Jia Tan.

https://git.tukaani.org/?p=xz.git;a=summary

This poor unpaid Fossdev probably has a ton of companies knocking on his door right now.

xtaran,
@xtaran@chaos.social avatar

@Aaron: Oh, and the now infamous "Simplify SECURITY.md" commit by is now also in that repo: https://git.tukaani.org/?p=xz.git;a=commit;h=af071ef7702debef4f1d324616a0137a5001c14c

So it's up to date with Github again (and now ahead of it).

stevel, to random
@stevel@hachyderm.io avatar

Presumably, along with all of us making sure our products and services are safe , the offence teams at the other governments will be busy going through the backdoor to understand how to exploit it -and then seeing if there any interesting targets that are vulnerable before the weekend is over. Busy weekend for all of us on call.

Conan_Kudo, to random
@Conan_Kudo@fosstodon.org avatar

Lasse Collin (the main maintainer) has now started working on a review of (credit to @jwf for the clever name!).

https://tukaani.org/xz-backdoor/

It's important to note how critical it was caught now: all the commercial distributions are making releases over the next 12-18 months: Red Hat with RHEL 10 in May 2025, SUSE with SLE 16 in fall 2025, and Canonical with Ubuntu 24.04 in April. It was key to infect their upstreams (Fedora, openSUSE, Debian) now.

Fortunately, it failed.

jwf, to opensource
@jwf@floss.social avatar
  • All
  • Subscribed
  • Moderated
  • Favorites
  • JUstTest
  • kavyap
  • DreamBathrooms
  • thenastyranch
  • magazineikmin
  • tacticalgear
  • cubers
  • Youngstown
  • mdbf
  • slotface
  • rosin
  • osvaldo12
  • ngwrru68w68
  • GTA5RPClips
  • provamag3
  • InstantRegret
  • everett
  • Durango
  • cisconetworking
  • khanakhh
  • ethstaker
  • tester
  • anitta
  • Leos
  • normalnudes
  • modclub
  • megavids
  • lostlight
  • All magazines