#jiat75 — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #jiat75, aggregated by home.social.
-
@echo_pbreyer Next #Jiat75 self-defense: "I was merely preparing everyone's systems for EU regulatory compliance!".
-
@echo_pbreyer Next #Jiat75 self-defense: "I was merely preparing everyone's systems for EU regulatory compliance!".
-
Yay, #Debian reduces #OpenSSH dependencies (in Debian Unstable for now) and removes #libsystemd dependency.
openssh (1:9.7p1-4) unstable; urgency=medium
* Rework systemd readiness notification and socket activation patches to not link against libsystemd (the former via an upstream patch).
* […]Thanks @cjwatson!
(via https://tracker.debian.org/news/1516548/accepted-openssh-197p1-4-source-into-unstable/)
#xz #xzbackdoor #xzorcist #JiaT75 #systemd #AttackSurfaceReduction
-
Yay, #Debian reduces #OpenSSH dependencies (in Debian Unstable for now) and removes #libsystemd dependency.
openssh (1:9.7p1-4) unstable; urgency=medium
* Rework systemd readiness notification and socket activation patches to not link against libsystemd (the former via an upstream patch).
* […]Thanks @cjwatson!
(via https://tracker.debian.org/news/1516548/accepted-openssh-197p1-4-source-into-unstable/)
#xz #xzbackdoor #xzorcist #JiaT75 #systemd #AttackSurfaceReduction
-
Do you remember when AT&T rolled back the ksh repository to a version 8 years old dismissing all the changes made in the last years by contributors?
Maybe we can do the same with the last two years of xz-utils? -
Woah, that xz backdoor *is* nasty.
Thanks #JiaT75 for nothing I guess. :P
-
@Aaron: Oh, and the now infamous "Simplify SECURITY.md" commit by #JiaT75 is now also in that repo: https://git.tukaani.org/?p=xz.git;a=commit;h=af071ef7702debef4f1d324616a0137a5001c14c
So it's up to date with Github again (and now ahead of it). #xz #xzorcist #xzbackdoor
-
@Aaron: Oh, and the now infamous "Simplify SECURITY.md" commit by #JiaT75 is now also in that repo: https://git.tukaani.org/?p=xz.git;a=commit;h=af071ef7702debef4f1d324616a0137a5001c14c
So it's up to date with Github again (and now ahead of it). #xz #xzorcist #xzbackdoor
-
@vaurora: In this case it was rather "not enough people involved" istead of "too many involved": See #busfactor and https://xkcd.com/2347 #xkcd2347
This was only possible because the original maintainer did that work alone and seems to have been close to a #burnout and urgently needed someone to step in. So it was easy to get the co-maintainer position without long-time #trust being involved.
-
@vaurora: In this case it was rather "not enough people involved" istead of "too many involved": See #busfactor and https://xkcd.com/2347 #xkcd2347
This was only possible because the original maintainer did that work alone and seems to have been close to a #burnout and urgently needed someone to step in. So it was easy to get the co-maintainer position without long-time #trust being involved.
-
@joeyh: There still seems a week-old copy on https://git.tukaani.org/?p=xz.git;a=summary #xz #JiaT75 #xzbackdoor
The latest change I remember (the infamous "simplification of SECURITY.md") is not in there, though, so it seems not up to date.
-
@joeyh: There still seems a week-old copy on https://git.tukaani.org/?p=xz.git;a=summary #xz #JiaT75 #xzbackdoor
The latest change I remember (the infamous "simplification of SECURITY.md") is not in there, though, so it seems not up to date.
-
@joeyh @effigies: #JiaT75 seems to have tried to get code into zstd, too: https://github.com/JiaT75/zstd/branches/all
Interestingly he force-pushed all these branches at the same time a few hours ago. Maybe to hide some more dirt he was planning to get into other compression libraries? (Found by @ollibaba in https://chaos.social/@ollibaba/112180492530810421)
-
@joeyh @effigies: #JiaT75 seems to have tried to get code into zstd, too: https://github.com/JiaT75/zstd/branches/all
Interestingly he force-pushed all these branches at the same time a few hours ago. Maybe to hide some more dirt he was planning to get into other compression libraries? (Found by @ollibaba in https://chaos.social/@ollibaba/112180492530810421)
-
The backdoor's source code ?
it was on GitHub
in a commit visible in a public repotherefore
OpenAI might have been training ChatGPT on it *already*
or other folks training their own 'code gen' LLMs on it
"But I can just blindly trust whatever code snippet that this LLM recommends! Right? Right?!"
*cough*
-
The backdoor's source code ?
it was on GitHub
in a commit visible in a public repotherefore
OpenAI might have been training ChatGPT on it *already*
or other folks training their own 'code gen' LLMs on it
"But I can just blindly trust whatever code snippet that this LLM recommends! Right? Right?!"
*cough*
-
It appears the maintainer of #xz had been targeted personally, and his health situation was exploited so that the likely perpetrator of the xz backdoor could take over the repository. #jiat75 https://www.mail-archive.com/xz-devel@tukaani.org/msg00571.html
-
It appears the maintainer of #xz had been targeted personally, and his health situation was exploited so that the likely perpetrator of the xz backdoor could take over the repository. #jiat75 https://www.mail-archive.com/xz-devel@tukaani.org/msg00571.html
-
@mirabilos @rysiek You made me look, and @QubesOS ships liblzma 5.4.1 in dom0.
As it turns out, 5.4.1 was _also_ released by #JiaT75.
It looks like there is already an open issue on the Qubes issue tracker, so they are aware of it.