Since everyone needs to share their opinion about the "xz" thing, here's mine:
Not everyone needs to share their opinion about the "xz" thing.
#xz
検索
There is a lot of talk about how lucky we were. And that somehow this is a bad thing.
I want to bring up the Birthday Paradox:
https://betterexplained.com/articles/understanding-the-birthday-paradox/
It is extremely lucky for you to have a person in the room with the same birthday date as yours. It is though quite reliably true that in a room of more than 70 people there will be at least one pair of people with a same birthday date.
Opening the code, and encouraging tinkering with it is how we bring more people in the room.
#xz
While everyone has been talking about #xz's backdoor I've been working on a patch for an AlmaLinux kernel vulnerability (CVE-2024-1086) that #rhel has yet to release a fix for (though #centos stream is patched). It's quite a nasty privilege escalation vulnerability so I suggest updating ASAP.
https://jonathanspw.com/posts/2024-03-31-dealing-with-cve-2024-1086/
Full production kernel builds provided within, as well as live kpatches (with no warranty/guarantee of course).
Kernel updates expected to hit #AlmaLinux repositories on Monday.
There are a lot of really bad takes right now about what can prevent the next #xz backdoor, with some pitching products and services that wouldn't have prevented anything in this scenario. They come across to me as this guy:
I'm personally interested in three aspect of this #xz #liblzma issue which are all open questions for me at this point:
1. learn what to look for in PRs and diffs
2. how to indicate bad actors in issue trackers and mailing lists
3. who is behind this xz issue (investigative journalism and digital forensics)
I found this blog post by @[email protected] that has well documented the events regarding this recent issue which definitely worth reading:
https://boehs.org/node/everything-i-know-about-the-xz-backdoor
Regarding the #xz #liblzma recent story, I believe we all (thise who care about #FLOSS) should read this well-written article:
https://robmensching.com/blog/posts/2024/03/30/a-microcosm-of-the-interactions-in-open-source-projects/
Everyone is having opinions about #xz and its creator. Working on a FOSS project in your free time can be a lot of fun but is also a thankless task. Even more so if you are doing it alone.
If you use open source software, also consider helping out with the projects. Don't be entitled. No-one owes you their time and effort.
If you use open source software, also consider helping out with the projects. Don't be entitled. No-one owes you their time and effort.
Lasse Colin posted an update on the #xz #openssh backdoor situation. It doesn't give a lot of details, but still useful as a primary source of information.
TL;DR: Damage control is underway in the project, but it's been somewhat inhibited by #Github taking it down and suspending Lasse's account.
https://tukaani.org/xz-backdoor/
Upgrade your systems now!
The xz package has been backdoored
https://archlinux.org/news/the-xz-package-has-been-backdoored/
#ArchLinux #Linux #xz #security
🤯 1