home.social

#jiat75 — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #jiat75, aggregated by home.social.

fetched live
  1. @echo_pbreyer Next #Jiat75 self-defense: "I was merely preparing everyone's systems for EU regulatory compliance!".

  2. @echo_pbreyer Next #Jiat75 self-defense: "I was merely preparing everyone's systems for EU regulatory compliance!".

  3. Yay, #Debian reduces #OpenSSH dependencies (in Debian Unstable for now) and removes #libsystemd dependency.

    openssh (1:9.7p1-4) unstable; urgency=medium

    * Rework systemd readiness notification and socket activation patches to not link against libsystemd (the former via an upstream patch).
    * […]

    Thanks @cjwatson!

    (via tracker.debian.org/news/151654)

    #xz #xzbackdoor #xzorcist #JiaT75 #systemd #AttackSurfaceReduction

  4. Yay, #Debian reduces #OpenSSH dependencies (in Debian Unstable for now) and removes #libsystemd dependency.

    openssh (1:9.7p1-4) unstable; urgency=medium

    * Rework systemd readiness notification and socket activation patches to not link against libsystemd (the former via an upstream patch).
    * […]

    Thanks @cjwatson!

    (via tracker.debian.org/news/151654)

    #xz #xzbackdoor #xzorcist #JiaT75 #systemd #AttackSurfaceReduction

  5. Do you remember when AT&T rolled back the ksh repository to a version 8 years old dismissing all the changes made in the last years by contributors?
    Maybe we can do the same with the last two years of xz-utils?

  6. Woah, that xz backdoor *is* nasty.

    Thanks #JiaT75 for nothing I guess. :P

  7. @Aaron: Oh, and the now infamous "Simplify SECURITY.md" commit by #JiaT75 is now also in that repo: git.tukaani.org/?p=xz.git;a=co

    So it's up to date with Github again (and now ahead of it). #xz #xzorcist #xzbackdoor

  8. @Aaron: Oh, and the now infamous "Simplify SECURITY.md" commit by #JiaT75 is now also in that repo: git.tukaani.org/?p=xz.git;a=co

    So it's up to date with Github again (and now ahead of it). #xz #xzorcist #xzbackdoor

  9. @vaurora: In this case it was rather "not enough people involved" istead of "too many involved": See #busfactor and xkcd.com/2347 #xkcd2347

    This was only possible because the original maintainer did that work alone and seems to have been close to a #burnout and urgently needed someone to step in. So it was easy to get the co-maintainer position without long-time #trust being involved.

    #JiaT75 #xzorcist #xz #FLOSS

  10. @vaurora: In this case it was rather "not enough people involved" istead of "too many involved": See #busfactor and xkcd.com/2347 #xkcd2347

    This was only possible because the original maintainer did that work alone and seems to have been close to a #burnout and urgently needed someone to step in. So it was easy to get the co-maintainer position without long-time #trust being involved.

    #JiaT75 #xzorcist #xz #FLOSS

  11. @joeyh: There still seems a week-old copy on git.tukaani.org/?p=xz.git;a=su #xz #JiaT75 #xzbackdoor

    The latest change I remember (the infamous "simplification of SECURITY.md") is not in there, though, so it seems not up to date.

  12. @joeyh: There still seems a week-old copy on git.tukaani.org/?p=xz.git;a=su #xz #JiaT75 #xzbackdoor

    The latest change I remember (the infamous "simplification of SECURITY.md") is not in there, though, so it seems not up to date.

  13. @joeyh @effigies: #JiaT75 seems to have tried to get code into zstd, too: github.com/JiaT75/zstd/branche

    Interestingly he force-pushed all these branches at the same time a few hours ago. Maybe to hide some more dirt he was planning to get into other compression libraries? (Found by @ollibaba in chaos.social/@ollibaba/1121804)

  14. @joeyh @effigies: #JiaT75 seems to have tried to get code into zstd, too: github.com/JiaT75/zstd/branche

    Interestingly he force-pushed all these branches at the same time a few hours ago. Maybe to hide some more dirt he was planning to get into other compression libraries? (Found by @ollibaba in chaos.social/@ollibaba/1121804)

  15. The backdoor's source code ?

    it was on GitHub
    in a commit visible in a public repo

    therefore

    OpenAI might have been training ChatGPT on it *already*

    or other folks training their own 'code gen' LLMs on it

    "But I can just blindly trust whatever code snippet that this LLM recommends! Right? Right?!"

    *cough*

    #JiaT75
    #cve20243094
    #xz
    #lzma
    #liblzma
    #backdoor
    #openssh

    #ai
    #llm
    #ChatGpT
    #OpenAI
    #CoPilot
    #GitHub
    #codegen

  16. The backdoor's source code ?

    it was on GitHub
    in a commit visible in a public repo

    therefore

    OpenAI might have been training ChatGPT on it *already*

    or other folks training their own 'code gen' LLMs on it

    "But I can just blindly trust whatever code snippet that this LLM recommends! Right? Right?!"

    *cough*

    #JiaT75
    #cve20243094
    #xz
    #lzma
    #liblzma
    #backdoor
    #openssh

    #ai
    #llm
    #ChatGpT
    #OpenAI
    #CoPilot
    #GitHub
    #codegen

  17. It appears the maintainer of #xz had been targeted personally, and his health situation was exploited so that the likely perpetrator of the xz backdoor could take over the repository. #jiat75 mail-archive.com/xz-devel@tuka

  18. It appears the maintainer of #xz had been targeted personally, and his health situation was exploited so that the likely perpetrator of the xz backdoor could take over the repository. #jiat75 mail-archive.com/xz-devel@tuka

  19. @mirabilos @rysiek You made me look, and @QubesOS ships liblzma 5.4.1 in dom0.

    As it turns out, 5.4.1 was _also_ released by #JiaT75.

    It looks like there is already an open issue on the Qubes issue tracker, so they are aware of it.

    @solene @mwlucas

    #qubes #qubesos #Qubes_OS