home.social

#xz — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #xz, aggregated by home.social.

fetched live
  1. 💾 Ejercitando la paciencia con Manic Miner en verano 56k.es/fanta/ejercitando-la-pa

    Boby grabó en lo que sobraba de la Cara A con su cassette doble pletina el juego «Manic Miner». Lo grabó también en la cara B por aquello de tener otra copia de seguridad.

    Boby era buena gente pero realmente «no tenía muchas luces», no era «el lápiz más afilado del estuche» .... #xz #spectrum #zxspectrum #manicminer #zx80

  2. 💾 Ejercitando la paciencia con Manic Miner en verano 56k.es/fanta/ejercitando-la-pa

    Boby grabó en lo que sobraba de la Cara A con su cassette doble pletina el juego «Manic Miner». Lo grabó también en la cara B por aquello de tener otra copia de seguridad.

    Boby era buena gente pero realmente «no tenía muchas luces», no era «el lápiz más afilado del estuche» .... #xz #spectrum #zxspectrum #manicminer #zx80

  3. Błąd w 7-Zip umożliwia zdalne wykonanie kodu (RCE)

    Landon Peng z Lunbun LLC odkrył lukę typu przepełnienie bufora na stosie w 7zip – popularnym narzędziu do obsługi archiwów. TLDR: Błąd obecny jest prawdopodobnie we wszystkich wersjach 7-Zip do 26.02 włącznie i znajduje się w funkcji odpowiedzialnej za obsługę archiwów w formacie xz.Skuteczna eksploitacja może prowadzić do zdalnego wykonania kodu. Do przeprowadzenia...

    #WBiegu #Cve #Rce #Xz

    sekurak.pl/blad-w-7-zip-umozli

  4. Błąd w 7-Zip umożliwia zdalne wykonanie kodu (RCE)

    Landon Peng z Lunbun LLC odkrył lukę typu przepełnienie bufora na stosie w 7zip – popularnym narzędziu do obsługi archiwów. TLDR: Błąd obecny jest prawdopodobnie we wszystkich wersjach 7-Zip do 26.02 włącznie i znajduje się w funkcji odpowiedzialnej za obsługę archiwów w formacie xz.Skuteczna eksploitacja może prowadzić do zdalnego wykonania kodu. Do przeprowadzenia...

    #WBiegu #Cve #Rce #Xz

    sekurak.pl/blad-w-7-zip-umozli

  5. Contd. [en] Software Supply Chain or Software Politics

    2/2

    "Although no malicious functionality was identified, the case showed how #software #provenance and #governance relationships may create #strategic concerns that are not visible through traditional #technical #analysis." ...

    "#AI systems such as #Mythos may transform how governments identify software vulnerabilities, but vulnerabilities are only part of the strategic picture. The lessons of #XZ, #SolarWinds, and easyjson suggest that some of the most consequential risks may not emerge from #vulnerable code, but from the software ecosystem through which code is governed, trusted, and delivered."

    justsecurity.org/142183/hiding

    #supplychain #vulnerability #go #easyjson #vk #invasion #ukraine #russia

  6. [en] Software Supply Chain or Software Politics

    1/2

    "In 2025, a #software supply chain #vulnerability was discovered in the widely used #Go programming library #easyjson that drew scrutiny due to its association with engineers from the #Russian technology company #VK. The package was hosted on GitHub by a MailRu account, which is owned by VK, and the VK CEO was sanctioned in 2022 by the U.S. Treasury following the Russian #invasion of #Ukraine, due to being or having been a leader or official of the Government of #Russia, amongst other reasons." ...

    ./2

    #supplychain #ai #mythos #xz #solarwinds

  7. [en] Software Supply Chain or Software Politics

    1/2

    "In 2025, a #software supply chain #vulnerability was discovered in the widely used #Go programming library #easyjson that drew scrutiny due to its association with engineers from the #Russian technology company #VK. The package was hosted on GitHub by a MailRu account, which is owned by VK, and the VK CEO was sanctioned in 2022 by the U.S. Treasury following the Russian #invasion of #Ukraine, due to being or having been a leader or official of the Government of #Russia, amongst other reasons." ...

    ./2

    #supplychain #ai #mythos #xz #solarwinds

  8. The Internet Was Weeks Away From Disaster and No One Knew

    youtube.com/watch?v=aoag03mSuXQ

    This is a superb dive into the XZ hack, the history of open source, the challenges of relying on volunteers, encryption, and a bunch more. An hour absolutely worth your time.

    #opensource #FreeSoftware #xz #security

  9. The Internet Was Weeks Away From Disaster and No One Knew

    youtube.com/watch?v=aoag03mSuXQ

    This is a superb dive into the XZ hack, the history of open source, the challenges of relying on volunteers, encryption, and a bunch more. An hour absolutely worth your time.

    #opensource #FreeSoftware #xz #security

  10. Wau how entertaining and exiting way to tell the story of some while back happened XZ vulnerability. Not new, but good watch over the weekend.

    "The Internet Was Weeks Away From Disaster and No One Knew"

    youtube.com/watch?v=aoag03mSuXQ

    #security #opensource #xz

  11. Wau how entertaining and exiting way to tell the story of some while back happened XZ vulnerability. Not new, but good watch over the weekend.

    "The Internet Was Weeks Away From Disaster and No One Knew"

    youtube.com/watch?v=aoag03mSuXQ

    #security #opensource #xz

  12. Tää oli kyllä uskomaton tarina miten pienestä joskus voi asiat olla kiinni.

    Muistakaa tukea ihmisiä jotka tekevät omalla vapaa-ajallaan ja omaksi ja muiden iloksi asioita. Usein pyyteettömästi. ❤️

    youtu.be/aoag03mSuXQ

    #OpenSSH #XZ #LasseCollin

  13. Tää oli kyllä uskomaton tarina miten pienestä joskus voi asiat olla kiinni.

    Muistakaa tukea ihmisiä jotka tekevät omalla vapaa-ajallaan ja omaksi ja muiden iloksi asioita. Usein pyyteettömästi. ❤️

    youtu.be/aoag03mSuXQ

    #OpenSSH #XZ #LasseCollin

  14. An excellent video giving strong arguments why every single country should have a @sovtechfund like organization. Or better, an EU agency, in our case.

    The Internet Was Weeks Away From Disaster and No One Knew
    youtu.be/aoag03mSuXQ?si=vbfi9g

    #OpenSource #DigitalSovereignty #Internet #Sustainability #Linux #GNU #openssh #xz

  15. An excellent video giving strong arguments why every single country should have a @sovtechfund like organization. Or better, an EU agency, in our case.

    The Internet Was Weeks Away From Disaster and No One Knew
    youtu.be/aoag03mSuXQ?si=vbfi9g

    #OpenSource #DigitalSovereignty #Internet #Sustainability #Linux #GNU #openssh #xz

  16. Veritasium covers the #xz compromise. This is well done. It starts off explaining open source. It explains encryption and compression. It explains software dependencies. It explains how the back door would have worked. Good watch.

    #Backdoor #Veritasium #CVE #CVE20243094
    youtu.be/aoag03mSuXQ

  17. Veritasium covers the #xz compromise. This is well done. It starts off explaining open source. It explains encryption and compression. It explains software dependencies. It explains how the back door would have worked. Good watch.

    #Backdoor #Veritasium #CVE #CVE20243094
    youtu.be/aoag03mSuXQ

  18. Veritasium made a really good video about the XZ backdoor, with a quick but comprehensive rundown on how it (and therefore partially Linux and libraries as a whole) worked.
    #Linux #xz #OpenSource

    ---

    The Internet Was Weeks Away From Disaster and No One Knew - Veritasium
    youtube.com/watch?v=aoag03mSuXQ

  19. Veritasium made a really good video about the XZ backdoor, with a quick but comprehensive rundown on how it (and therefore partially Linux and libraries as a whole) worked.
    #Linux #xz #OpenSource

    ---

    The Internet Was Weeks Away From Disaster and No One Knew - Veritasium
    youtube.com/watch?v=aoag03mSuXQ

  20. The XZ supply chain attack episode from @veritasium

    This episode discusses the history, sequence of events and an explanation of the attack along with some speculation as to the threat actor involved.

    youtu.be/aoag03mSuXQ [52' 59"]

    #XZ #SupplyChainAttack #InfoSec #APT

  21. The XZ supply chain attack episode from @veritasium

    This episode discusses the history, sequence of events and an explanation of the attack along with some speculation as to the threat actor involved.

    youtu.be/aoag03mSuXQ [52' 59"]

    #XZ #SupplyChainAttack #InfoSec #APT

  22. #Veritasium did a video on how #SSH almost became compromised by #XZ, and along the way in a really easy to understand yet precise way explains so many things about the software freedom community that I am truly impressed.

    Deserves to be shared widely:

    youtube.com/watch?v=aoag03mSuXQ

  23. #Veritasium did a video on how #SSH almost became compromised by #XZ, and along the way in a really easy to understand yet precise way explains so many things about the software freedom community that I am truly impressed.

    Deserves to be shared widely:

    youtube.com/watch?v=aoag03mSuXQ

  24. Observation. Although it wasn't the case with older versions of #Debian, or perhaps older versions of #XZ, creating archives with xz on Debian, whether thru tar or xz directly, now uses all CPU cores instead of just one like it did before. Just noticed this after doing a fresh install of Debian 13 a while back on my desktop PC.

    #Linux

  25. Observation. Although it wasn't the case with older versions of #Debian, or perhaps older versions of #XZ, creating archives with xz on Debian, whether thru tar or xz directly, now uses all CPU cores instead of just one like it did before. Just noticed this after doing a fresh install of Debian 13 a while back on my desktop PC.

    #Linux

  26. Seguim amb bona #divulgació sobre l'#opensource. #Veritasium fa aquest fantàstic video que explica per tots els públics pero sense amagar coses com es va arribar a produir i arreglar la vulnerabilitat del #XZ que podría haver afectat a milions d'ordinadors i dispositius #Linux.

    Em flipa que ho expliquin tan bé, donant context i fent-ho tan entendible.

    youtube.com/watch?v=aoag03mSuXQ

  27. Seguim amb bona #divulgació sobre l'#opensource. #Veritasium fa aquest fantàstic video que explica per tots els públics pero sense amagar coses com es va arribar a produir i arreglar la vulnerabilitat del #XZ que podría haver afectat a milions d'ordinadors i dispositius #Linux.

    Em flipa que ho expliquin tan bé, donant context i fent-ho tan entendible.

    youtube.com/watch?v=aoag03mSuXQ

  28. @rriemann Re: backdoor, you state:

    > NixOS: affected and unaffected, slow to roll out updates

    But the sources you link don't state that NixOS was vulnerable to exploits, if I'm not mistaken. The backdoored code briefly landed in unstable, but wasn't exploitable due to 's unique build system. Furthermore, fixing it locally and distributing the fix without relying on the official distro cache/repos is much easier with NixOS, I would argue.

  29. @rriemann Re: #xz backdoor, you state:

    > NixOS: affected and unaffected, slow to roll out updates

    But the sources you link don't state that NixOS was vulnerable to exploits, if I'm not mistaken. The backdoored code briefly landed in unstable, but wasn't exploitable due to #NixOS's unique build system. Furthermore, fixing it locally and distributing the fix without relying on the official distro cache/repos is much easier with NixOS, I would argue.

  30. Archivierung und Kompression mit tar: Grundlagen, Optionen und Beispiele

    tar (Tape Archiver) ist das Standard-Archivierungswerkzeug unter Linux, das mehrere Dateien und Ordner zu einem einzigen Archiv bündelt. Im Gegensatz zu gzip, bzip2 und xz komprimiert tar nicht selbst, sondern arbeitet mit Kompressionstools zusammen (z, j, J). Es erhält vollständige Metadaten inklusive Berechtigungen und SELinux-Kontexte. Wichtige Optionen von tar -c (create) : Erstellt ein neues Archiv. -f (file name). : Gibt den Dateinamen des Archivs an. # Einen Ordner […]

    andreas-moor.de/archivierung-u

  31. Kompression mit zip: Grundlagen, Optionen und Beispiele

    zip ist das universellste Archivierungs- und Kompressionswerkzeug, das unter Linux, Windows und macOS funktioniert. Es kombiniert Archivierung und Kompression in einem Schritt und kann Ordner direkt verarbeiten – im Gegensatz zu gzip, bzip2 und xz. Ideal für plattformübergreifenden Dateiaustausch. Wichtige Optionen von zip -r : Rekursiv: Komprimiert Ordner und alle Unterordner (einzigartig bei zip). zip -r backup.zip ordner/ -d oder unzip : Entpackt eine .zip-Datei. unzip ist ein […]

    andreas-moor.de/kompression-mi

  32. Kompression mit bzip2 Linux: Grundlagen, Optionen und Beispiele

    bzip2 ist ein leistungsstarkes Kompressionswerkzeug unter Linux, das den Burrows-Wheeler-Algorithmus nutzt. Es erreicht eine deutlich bessere Kompressionsrate als gzip, benötigt dafür aber mehr Rechenzeit. Ideal für Speicherplatz-kritische Szenarien wie große Textdateien oder Logs. Wichtige Optionen von bzip2 -k : Originaldatei nach Kompression behalten. Standardmäßig wird die Eingabedatei gelöscht. bzip2 -k datei.txt -d oder bunzip2 (Alias) : Dekomprimiert eine .bz2-Datei. bunzip2 […]

    andreas-moor.de/kompression-mi

  33. Kompression mit gzip: Grundlagen, Optionen und Beispiele

    gzip ist eines der meistgenutzten Kompressionswerkzeuge unter Linux, das einzelne Dateien mit dem schnellen DEFLATE-Algorithmus komprimiert. Es ist besonders nützlich für alltägliche Kompressionsaufgaben, bei denen Geschwindigkeit wichtiger ist als maximale Speicherersparnis. Wichtige Optionen von gzip -k : Originaldatei nach Kompression behalten. Standardmäßig entfernt gzip die Eingabedatei nach Kompression. gzip -k datei.txt -d oder gunzip (Alias): Dekomprimiert eine .gz-Datei. […]

    andreas-moor.de/kompression-mi

  34. Playing around with compressing a directory structure full of XML files which are about 2MB each (one per directory) and which have a lot of commonality.

    It included about 14GB of files in total. With gzip/bzip2/zstd/zip it goes down to ~1GiB (#gzip -> zstd -> bzip2 in order of decreasing size). With #xz it went down to about 67MiB. Huge difference for this use case. Decompressing it was MUCH faster with xz (5.0s vs 33.2s when writing to /dev/null - xz took 5X longer to compress than pigz)

  35. Animated xkcd 2347.

    I originally made this after the backdooring attempt of the XZ Utils repo by some entity named Jia Tan was discovered, but without sound. Finally, it is available in stereo, headphones recommended.
    Damned, the whole thing was discovered in march 2024! The relevance of this clip might be like a sine wave, hopefully not, but we'll see :P

    #b3d #blender3D #npr #xkcd #xkcd2347 #xz #backdoor #infrastructure

  36. Wasn't #Bellingcat doing an entire investigation thing around Jia Tan and the xz stuff.

    What happened there?

    #JiaTan #XZ

  37. RE: infosec.exchange/@joshbressers

    Subscribe to the Open Source Security podcast (opensourcesecurity.io) on your favorite platform and check out the latest episode where I am talking about how I did the #XZ Utils analysis in #Debian.

  38. 🎉 Behold, the groundbreaking revelation: #Xz is not the Holy Grail of data formats! 🚀 Apparently, using xz for digital preservation is like using a sieve as a bucket—bound to fail. Who knew? 🤦‍♂️ Stick to #bzip2, #gzip, or #lzip if you want actual functionality and avoid sinking your data into the abyss of inadequacy. 🔍💾
    nongnu.org/lzip/xz_inadequate. #dataformats #digitalpreservation #HackerNews #ngated