home.social

#xz — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #xz, aggregated by home.social.

  1. Half a Second

    The Backdoor That Almost Broke the Internet, and the Invisible Labor Beneath It

    half-second.com/

    #freesoftware #funding #xz

  2. Half a Second

    The Backdoor That Almost Broke the Internet, and the Invisible Labor Beneath It

    half-second.com/

    #freesoftware #funding #xz

  3. 💾 Ejercitando la paciencia con Manic Miner en verano 56k.es/fanta/ejercitando-la-pa

    Boby grabó en lo que sobraba de la Cara A con su cassette doble pletina el juego «Manic Miner». Lo grabó también en la cara B por aquello de tener otra copia de seguridad.

    Boby era buena gente pero realmente «no tenía muchas luces», no era «el lápiz más afilado del estuche» .... #xz #spectrum #zxspectrum #manicminer #zx80

  4. 💾 Ejercitando la paciencia con Manic Miner en verano 56k.es/fanta/ejercitando-la-pa

    Boby grabó en lo que sobraba de la Cara A con su cassette doble pletina el juego «Manic Miner». Lo grabó también en la cara B por aquello de tener otra copia de seguridad.

    Boby era buena gente pero realmente «no tenía muchas luces», no era «el lápiz más afilado del estuche» .... #xz #spectrum #zxspectrum #manicminer #zx80

  5. Błąd w 7-Zip umożliwia zdalne wykonanie kodu (RCE)

    Landon Peng z Lunbun LLC odkrył lukę typu przepełnienie bufora na stosie w 7zip – popularnym narzędziu do obsługi archiwów. TLDR: Błąd obecny jest prawdopodobnie we wszystkich wersjach 7-Zip do 26.02 włącznie i znajduje się w funkcji odpowiedzialnej za obsługę archiwów w formacie xz.Skuteczna eksploitacja może prowadzić do zdalnego wykonania kodu. Do przeprowadzenia...

    #WBiegu #Cve #Rce #Xz

    sekurak.pl/blad-w-7-zip-umozli

  6. Błąd w 7-Zip umożliwia zdalne wykonanie kodu (RCE)

    Landon Peng z Lunbun LLC odkrył lukę typu przepełnienie bufora na stosie w 7zip – popularnym narzędziu do obsługi archiwów. TLDR: Błąd obecny jest prawdopodobnie we wszystkich wersjach 7-Zip do 26.02 włącznie i znajduje się w funkcji odpowiedzialnej za obsługę archiwów w formacie xz.Skuteczna eksploitacja może prowadzić do zdalnego wykonania kodu. Do przeprowadzenia...

    #WBiegu #Cve #Rce #Xz

    sekurak.pl/blad-w-7-zip-umozli

  7. Błąd w 7-Zip umożliwia zdalne wykonanie kodu (RCE)

    Landon Peng z Lunbun LLC odkrył lukę typu przepełnienie bufora na stosie w 7zip – popularnym narzędziu do obsługi archiwów. TLDR: Błąd obecny jest prawdopodobnie we wszystkich wersjach 7-Zip do 26.02 włącznie i znajduje się w funkcji odpowiedzialnej za obsługę archiwów w formacie xz.Skuteczna eksploitacja może prowadzić do zdalnego wykonania kodu. Do przeprowadzenia...

    #WBiegu #Cve #Rce #Xz

    sekurak.pl/blad-w-7-zip-umozli

  8. Błąd w 7-Zip umożliwia zdalne wykonanie kodu (RCE)

    Landon Peng z Lunbun LLC odkrył lukę typu przepełnienie bufora na stosie w 7zip – popularnym narzędziu do obsługi archiwów. TLDR: Błąd obecny jest prawdopodobnie we wszystkich wersjach 7-Zip do 26.02 włącznie i znajduje się w funkcji odpowiedzialnej za obsługę archiwów w formacie xz.Skuteczna eksploitacja może prowadzić do zdalnego wykonania kodu. Do przeprowadzenia...

    #WBiegu #Cve #Rce #Xz

    sekurak.pl/blad-w-7-zip-umozli

  9. Błąd w 7-Zip umożliwia zdalne wykonanie kodu (RCE)

    Landon Peng z Lunbun LLC odkrył lukę typu przepełnienie bufora na stosie w 7zip – popularnym narzędziu do obsługi archiwów. TLDR: Błąd obecny jest prawdopodobnie we wszystkich wersjach 7-Zip do 26.02 włącznie i znajduje się w funkcji odpowiedzialnej za obsługę archiwów w formacie xz.Skuteczna eksploitacja może prowadzić do zdalnego wykonania kodu. Do przeprowadzenia...

    #WBiegu #Cve #Rce #Xz

    sekurak.pl/blad-w-7-zip-umozli

  10. Contd. [en] Software Supply Chain or Software Politics

    2/2

    "Although no malicious functionality was identified, the case showed how #software #provenance and #governance relationships may create #strategic concerns that are not visible through traditional #technical #analysis." ...

    "#AI systems such as #Mythos may transform how governments identify software vulnerabilities, but vulnerabilities are only part of the strategic picture. The lessons of #XZ, #SolarWinds, and easyjson suggest that some of the most consequential risks may not emerge from #vulnerable code, but from the software ecosystem through which code is governed, trusted, and delivered."

    justsecurity.org/142183/hiding

    #supplychain #vulnerability #go #easyjson #vk #invasion #ukraine #russia

  11. Contd. [en] Software Supply Chain or Software Politics

    2/2

    "Although no malicious functionality was identified, the case showed how #software #provenance and #governance relationships may create #strategic concerns that are not visible through traditional #technical #analysis." ...

    "#AI systems such as #Mythos may transform how governments identify software vulnerabilities, but vulnerabilities are only part of the strategic picture. The lessons of #XZ, #SolarWinds, and easyjson suggest that some of the most consequential risks may not emerge from #vulnerable code, but from the software ecosystem through which code is governed, trusted, and delivered."

    justsecurity.org/142183/hiding

    #supplychain #vulnerability #go #easyjson #vk #invasion #ukraine #russia

  12. [en] Software Supply Chain or Software Politics

    1/2

    "In 2025, a #software supply chain #vulnerability was discovered in the widely used #Go programming library #easyjson that drew scrutiny due to its association with engineers from the #Russian technology company #VK. The package was hosted on GitHub by a MailRu account, which is owned by VK, and the VK CEO was sanctioned in 2022 by the U.S. Treasury following the Russian #invasion of #Ukraine, due to being or having been a leader or official of the Government of #Russia, amongst other reasons." ...

    ./2

    #supplychain #ai #mythos #xz #solarwinds

  13. [en] Software Supply Chain or Software Politics

    1/2

    "In 2025, a #software supply chain #vulnerability was discovered in the widely used #Go programming library #easyjson that drew scrutiny due to its association with engineers from the #Russian technology company #VK. The package was hosted on GitHub by a MailRu account, which is owned by VK, and the VK CEO was sanctioned in 2022 by the U.S. Treasury following the Russian #invasion of #Ukraine, due to being or having been a leader or official of the Government of #Russia, amongst other reasons." ...

    ./2

    #supplychain #ai #mythos #xz #solarwinds

  14. [en] Software Supply Chain or Software Politics

    1/2

    "In 2025, a #software supply chain #vulnerability was discovered in the widely used #Go programming library #easyjson that drew scrutiny due to its association with engineers from the #Russian technology company #VK. The package was hosted on GitHub by a MailRu account, which is owned by VK, and the VK CEO was sanctioned in 2022 by the U.S. Treasury following the Russian #invasion of #Ukraine, due to being or having been a leader or official of the Government of #Russia, amongst other reasons." ...

    ./2

    #supplychain #ai #mythos #xz #solarwinds

  15. [en] Software Supply Chain or Software Politics

    1/2

    "In 2025, a #software supply chain #vulnerability was discovered in the widely used #Go programming library #easyjson that drew scrutiny due to its association with engineers from the #Russian technology company #VK. The package was hosted on GitHub by a MailRu account, which is owned by VK, and the VK CEO was sanctioned in 2022 by the U.S. Treasury following the Russian #invasion of #Ukraine, due to being or having been a leader or official of the Government of #Russia, amongst other reasons." ...

    ./2

    #supplychain #ai #mythos #xz #solarwinds

  16. [en] Software Supply Chain or Software Politics

    1/2

    "In 2025, a #software supply chain #vulnerability was discovered in the widely used #Go programming library #easyjson that drew scrutiny due to its association with engineers from the #Russian technology company #VK. The package was hosted on GitHub by a MailRu account, which is owned by VK, and the VK CEO was sanctioned in 2022 by the U.S. Treasury following the Russian #invasion of #Ukraine, due to being or having been a leader or official of the Government of #Russia, amongst other reasons." ...

    ./2

    #supplychain #ai #mythos #xz #solarwinds

  17. The Internet Was Weeks Away From Disaster and No One Knew

    youtube.com/watch?v=aoag03mSuXQ

    This is a superb dive into the XZ hack, the history of open source, the challenges of relying on volunteers, encryption, and a bunch more. An hour absolutely worth your time.

    #opensource #FreeSoftware #xz #security

  18. The Internet Was Weeks Away From Disaster and No One Knew

    youtube.com/watch?v=aoag03mSuXQ

    This is a superb dive into the XZ hack, the history of open source, the challenges of relying on volunteers, encryption, and a bunch more. An hour absolutely worth your time.

    #opensource #FreeSoftware #xz #security

  19. Wau how entertaining and exiting way to tell the story of some while back happened XZ vulnerability. Not new, but good watch over the weekend.

    "The Internet Was Weeks Away From Disaster and No One Knew"

    youtube.com/watch?v=aoag03mSuXQ

    #security #opensource #xz

  20. Wau how entertaining and exiting way to tell the story of some while back happened XZ vulnerability. Not new, but good watch over the weekend.

    "The Internet Was Weeks Away From Disaster and No One Knew"

    youtube.com/watch?v=aoag03mSuXQ

    #security #opensource #xz

  21. Tää oli kyllä uskomaton tarina miten pienestä joskus voi asiat olla kiinni.

    Muistakaa tukea ihmisiä jotka tekevät omalla vapaa-ajallaan ja omaksi ja muiden iloksi asioita. Usein pyyteettömästi. ❤️

    youtu.be/aoag03mSuXQ

    #OpenSSH #XZ #LasseCollin

  22. Tää oli kyllä uskomaton tarina miten pienestä joskus voi asiat olla kiinni.

    Muistakaa tukea ihmisiä jotka tekevät omalla vapaa-ajallaan ja omaksi ja muiden iloksi asioita. Usein pyyteettömästi. ❤️

    youtu.be/aoag03mSuXQ

    #OpenSSH #XZ #LasseCollin

  23. An excellent video giving strong arguments why every single country should have a @sovtechfund like organization. Or better, an EU agency, in our case.

    The Internet Was Weeks Away From Disaster and No One Knew
    youtu.be/aoag03mSuXQ?si=vbfi9g

    #OpenSource #DigitalSovereignty #Internet #Sustainability #Linux #GNU #openssh #xz

  24. An excellent video giving strong arguments why every single country should have a @sovtechfund like organization. Or better, an EU agency, in our case.

    The Internet Was Weeks Away From Disaster and No One Knew
    youtu.be/aoag03mSuXQ?si=vbfi9g

    #OpenSource #DigitalSovereignty #Internet #Sustainability #Linux #GNU #openssh #xz

  25. Veritasium covers the #xz compromise. This is well done. It starts off explaining open source. It explains encryption and compression. It explains software dependencies. It explains how the back door would have worked. Good watch.

    #Backdoor #Veritasium #CVE #CVE20243094
    youtu.be/aoag03mSuXQ

  26. Veritasium covers the #xz compromise. This is well done. It starts off explaining open source. It explains encryption and compression. It explains software dependencies. It explains how the back door would have worked. Good watch.

    #Backdoor #Veritasium #CVE #CVE20243094
    youtu.be/aoag03mSuXQ

  27. Veritasium covers the #xz compromise. This is well done. It starts off explaining open source. It explains encryption and compression. It explains software dependencies. It explains how the back door would have worked. Good watch.

    #Backdoor #Veritasium #CVE #CVE20243094
    youtu.be/aoag03mSuXQ

  28. Veritasium covers the #xz compromise. This is well done. It starts off explaining open source. It explains encryption and compression. It explains software dependencies. It explains how the back door would have worked. Good watch.

    #Backdoor #Veritasium #CVE #CVE20243094
    youtu.be/aoag03mSuXQ

  29. Veritasium covers the #xz compromise. This is well done. It starts off explaining open source. It explains encryption and compression. It explains software dependencies. It explains how the back door would have worked. Good watch.

    #Backdoor #Veritasium #CVE #CVE20243094
    youtu.be/aoag03mSuXQ

  30. Veritasium made a really good video about the XZ backdoor, with a quick but comprehensive rundown on how it (and therefore partially Linux and libraries as a whole) worked.
    #Linux #xz #OpenSource

    ---

    The Internet Was Weeks Away From Disaster and No One Knew - Veritasium
    youtube.com/watch?v=aoag03mSuXQ

  31. Veritasium made a really good video about the XZ backdoor, with a quick but comprehensive rundown on how it (and therefore partially Linux and libraries as a whole) worked.
    #Linux #xz #OpenSource

    ---

    The Internet Was Weeks Away From Disaster and No One Knew - Veritasium
    youtube.com/watch?v=aoag03mSuXQ

  32. The XZ supply chain attack episode from @veritasium

    This episode discusses the history, sequence of events and an explanation of the attack along with some speculation as to the threat actor involved.

    youtu.be/aoag03mSuXQ [52' 59"]

    #XZ #SupplyChainAttack #InfoSec #APT

  33. The XZ supply chain attack episode from @veritasium

    This episode discusses the history, sequence of events and an explanation of the attack along with some speculation as to the threat actor involved.

    youtu.be/aoag03mSuXQ [52' 59"]

    #XZ #SupplyChainAttack #InfoSec #APT

  34. #Veritasium did a video on how #SSH almost became compromised by #XZ, and along the way in a really easy to understand yet precise way explains so many things about the software freedom community that I am truly impressed.

    Deserves to be shared widely:

    youtube.com/watch?v=aoag03mSuXQ

  35. #Veritasium did a video on how #SSH almost became compromised by #XZ, and along the way in a really easy to understand yet precise way explains so many things about the software freedom community that I am truly impressed.

    Deserves to be shared widely:

    youtube.com/watch?v=aoag03mSuXQ

  36. Observation. Although it wasn't the case with older versions of #Debian, or perhaps older versions of #XZ, creating archives with xz on Debian, whether thru tar or xz directly, now uses all CPU cores instead of just one like it did before. Just noticed this after doing a fresh install of Debian 13 a while back on my desktop PC.

    #Linux

  37. Observation. Although it wasn't the case with older versions of #Debian, or perhaps older versions of #XZ, creating archives with xz on Debian, whether thru tar or xz directly, now uses all CPU cores instead of just one like it did before. Just noticed this after doing a fresh install of Debian 13 a while back on my desktop PC.

    #Linux

  38. Seguim amb bona #divulgació sobre l'#opensource. #Veritasium fa aquest fantàstic video que explica per tots els públics pero sense amagar coses com es va arribar a produir i arreglar la vulnerabilitat del #XZ que podría haver afectat a milions d'ordinadors i dispositius #Linux.

    Em flipa que ho expliquin tan bé, donant context i fent-ho tan entendible.

    youtube.com/watch?v=aoag03mSuXQ

  39. Seguim amb bona #divulgació sobre l'#opensource. #Veritasium fa aquest fantàstic video que explica per tots els públics pero sense amagar coses com es va arribar a produir i arreglar la vulnerabilitat del #XZ que podría haver afectat a milions d'ordinadors i dispositius #Linux.

    Em flipa que ho expliquin tan bé, donant context i fent-ho tan entendible.

    youtube.com/watch?v=aoag03mSuXQ

  40. @rriemann Re: backdoor, you state:

    > NixOS: affected and unaffected, slow to roll out updates

    But the sources you link don't state that NixOS was vulnerable to exploits, if I'm not mistaken. The backdoored code briefly landed in unstable, but wasn't exploitable due to 's unique build system. Furthermore, fixing it locally and distributing the fix without relying on the official distro cache/repos is much easier with NixOS, I would argue.

  41. @rriemann Re: #xz backdoor, you state:

    > NixOS: affected and unaffected, slow to roll out updates

    But the sources you link don't state that NixOS was vulnerable to exploits, if I'm not mistaken. The backdoored code briefly landed in unstable, but wasn't exploitable due to #NixOS's unique build system. Furthermore, fixing it locally and distributing the fix without relying on the official distro cache/repos is much easier with NixOS, I would argue.

  42. Archivierung und Kompression mit tar: Grundlagen, Optionen und Beispiele

    tar (Tape Archiver) ist das Standard-Archivierungswerkzeug unter Linux, das mehrere Dateien und Ordner zu einem einzigen Archiv bündelt. Im Gegensatz zu gzip, bzip2 und xz komprimiert tar nicht selbst, sondern arbeitet mit Kompressionstools zusammen (z, j, J). Es erhält vollständige Metadaten inklusive Berechtigungen und SELinux-Kontexte. Wichtige Optionen von tar -c (create) : Erstellt ein neues Archiv. -f (file name). : Gibt den Dateinamen des Archivs an. # Einen Ordner […]

    andreas-moor.de/archivierung-u

  43. Archivierung und Kompression mit tar: Grundlagen, Optionen und Beispiele

    tar (Tape Archiver) ist das Standard-Archivierungswerkzeug unter Linux, das mehrere Dateien und Ordner zu einem einzigen Archiv bündelt. Im Gegensatz zu gzip, bzip2 und xz komprimiert tar nicht selbst, sondern arbeitet mit Kompressionstools zusammen (z, j, J). Es erhält vollständige Metadaten inklusive Berechtigungen und SELinux-Kontexte. Wichtige Optionen von tar -c (create) : Erstellt ein neues Archiv. -f (file name). : Gibt den Dateinamen des Archivs an. # Einen Ordner […]

    andreas-moor.de/archivierung-u

  44. Archivierung und Kompression mit tar: Grundlagen, Optionen und Beispiele

    tar (Tape Archiver) ist das Standard-Archivierungswerkzeug unter Linux, das mehrere Dateien und Ordner zu einem einzigen Archiv bündelt. Im Gegensatz zu gzip, bzip2 und xz komprimiert tar nicht selbst, sondern arbeitet mit Kompressionstools zusammen (z, j, J). Es erhält vollständige Metadaten inklusive Berechtigungen und SELinux-Kontexte. Wichtige Optionen von tar -c : Erstellt ein neues Archiv. (create) -f : Gibt den Dateinamen des Archivs an (file name). tar -cf backup.tar […]

    andreas-moor.de/archivierung-u

  45. Kompression mit zip: Grundlagen, Optionen und Beispiele

    zip ist das universellste Archivierungs- und Kompressionswerkzeug, das unter Linux, Windows und macOS funktioniert. Es kombiniert Archivierung und Kompression in einem Schritt und kann Ordner direkt verarbeiten – im Gegensatz zu gzip, bzip2 und xz. Ideal für plattformübergreifenden Dateiaustausch. Wichtige Optionen von zip -r : Rekursiv: Komprimiert Ordner und alle Unterordner (einzigartig bei zip). zip -r backup.zip ordner/ -d oder unzip : Entpackt eine .zip-Datei. unzip ist ein […]

    andreas-moor.de/kompression-mi