#xzbackdoor — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #xzbackdoor, aggregated by home.social.
-
I had to deal a bit with the "Supply-chain Levels for Software Artifacts" (SLSA) "standard":
https://slsa.dev/IMO it's a joke, since they do not properly deal with threats from "Includ[ing] a vulnerable dependency (library, base image, bundled file, etc.)". They essentially say "A future version of this standard might deal with that":
https://slsa.dev/spec/v1.2/threatsThis has been the main entry point of the past supply chain attacks (XZ backdoor, litellm, Shai-Hulud, ...). A supply-chain security standard that doesn't properly deal with vulnerabilities in dependencies completely misses the point. It's like installing alarms on your windows (to catch burglars trying to enter your home through the windows) when your front door doesn't have a lock.
#SLSA #supplychain #supplychainsecurity #xzbackdoor #ShaiHulud #litellm
-
https://liblzma.so/ I made a thing. impulse control is for suckers
-
Lasse Collin (the developer of xz-utils) has found out how to accept donations without breaking the Finnish money collection law:
https://github.com/tukaani-project/xz/issues/105#issuecomment-2599004098He has created an account on #LiberaPay with a restriction to not accept donations from Finns or people living in Finland:
https://liberapay.com/Larhzu/ -
Was wissen wir eigentlich über «Jia Tan»? Ich habe mich mal auf eine Spurensuche begeben. Und dabei herausgefunden, dass man mit der Sicherheitslücke wohl mehrere Milliarden hätte verdienen können.
Ich nehme euch gerne mit auf diese Reise und die Schlussfolgerungen, die sich daraus ergeben.
#JiaTan #xz #Backdoor #xzBackdoor #DNIP
https://dnip.ch/2024/05/14/spurensuche-jia-tan-xz/ -
Did you miss last week's Linux Update newsletter? Read it now and subscribe to get it free every week https://mailchi.mp/linux-magazine.com/linux-update-preventing-dns-subdomain-hijacking #DNS #security #hijacking #Canonical #LTS #vulnerability #xzbackdoor #Linux #OpenSource #ProxyChains #events #jobs #LibrePlanet #DrupalCon #FOSS
-
Happy (very punctual) #FiveMinuteFriday. Today we're talking about some changes we are making in light of the #XZBackdoor. tldr; the Trusted Contributors program will be doing a bit more #TrustButVerify. Read more about Trusted Contributors at https://www.puppet.com/ecosystem/contribute/trusted-contributors or download the scanner module at https://forge.puppet.com/puppetlabs/xzscanner and check your infrastructure today.
-
Happy (very punctual) #FiveMinuteFriday. Today we're talking about some changes we are making in light of the #XZBackdoor. tldr; the Trusted Contributors program will be doing a bit more #TrustButVerify. Read more about Trusted Contributors at https://www.puppet.com/ecosystem/contribute/trusted-contributors or download the scanner module at https://forge.puppet.com/puppetlabs/xzscanner and check your infrastructure today.
-
Latest episode of The Download is out, this one covers all the #xzBackdoor news, updates on GitHub Copilot for the CLI, big new releases from #Bun and #Babylonjs and of course, Beyoncé https://www.youtube.com/watch?v=TrqiT_a8zgU
-
Yay, #Debian reduces #OpenSSH dependencies (in Debian Unstable for now) and removes #libsystemd dependency.
openssh (1:9.7p1-4) unstable; urgency=medium
* Rework systemd readiness notification and socket activation patches to not link against libsystemd (the former via an upstream patch).
* […]Thanks @cjwatson!
(via https://tracker.debian.org/news/1516548/accepted-openssh-197p1-4-source-into-unstable/)
#xz #xzbackdoor #xzorcist #JiaT75 #systemd #AttackSurfaceReduction
-
Do you remember when AT&T rolled back the ksh repository to a version 8 years old dismissing all the changes made in the last years by contributors?
Maybe we can do the same with the last two years of xz-utils? -
So if I Interpret the data correctly then #yocto / #openEmbedded based Linux systems are not vulnerable to the #xzbackdoor due to not updating very quick. xz is at version 5.4.6 in the openembedded-core layer.
I don't see anything that would have prevented being vulnerable though, the openembedded-core layer does
- contain the libsystemd patch and thus pulls in xz when building a systemd enabled distro
- uses the release-tarballs of xz -
@Aaron: Oh, and the now infamous "Simplify SECURITY.md" commit by #JiaT75 is now also in that repo: https://git.tukaani.org/?p=xz.git;a=commit;h=af071ef7702debef4f1d324616a0137a5001c14c
So it's up to date with Github again (and now ahead of it). #xz #xzorcist #xzbackdoor
-
@joeyh: There still seems a week-old copy on https://git.tukaani.org/?p=xz.git;a=summary #xz #JiaT75 #xzbackdoor
The latest change I remember (the infamous "simplification of SECURITY.md") is not in there, though, so it seems not up to date.