home.social

#xzbackdoor — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #xzbackdoor, aggregated by home.social.

fetched live
  1. I had to deal a bit with the "Supply-chain Levels for Software Artifacts" (SLSA) "standard":
    slsa.dev/

    IMO it's a joke, since they do not properly deal with threats from "Includ[ing] a vulnerable dependency (library, base image, bundled file, etc.)". They essentially say "A future version of this standard might deal with that":
    slsa.dev/spec/v1.2/threats

    This has been the main entry point of the past supply chain attacks (XZ backdoor, litellm, Shai-Hulud, ...). A supply-chain security standard that doesn't properly deal with vulnerabilities in dependencies completely misses the point. It's like installing alarms on your windows (to catch burglars trying to enter your home through the windows) when your front door doesn't have a lock.

    #SLSA #supplychain #supplychainsecurity #xzbackdoor #ShaiHulud #litellm

  2. @mike One one hand, governments and corporations shouldn't have to pay for using open-source software since it is explicitly provided Free....
    On the other hand, it's not really fair when some poor maintainer finds themselves maintaining a project that a lot of people really depend on (the #XZbackdoor comes to mind).

  3. Lasse Collin (the developer of xz-utils) has found out how to accept donations without breaking the Finnish money collection law:
    github.com/tukaani-project/xz/

    He has created an account on #LiberaPay with a restriction to not accept donations from Finns or people living in Finland:
    liberapay.com/Larhzu/

    #OpenSource #XZBackdoor #XZUtils #XZ

  4. I thought the case of the #xzbackdoor would be a really good way to make students aware of the many different dimensions of computing, and the “The Philosophy of the Open Source Pledge” vladh.net/the-philosophy-of-th, which I assigned as reading, highlights many of the issues in a concise fashion.

    Most students: 😴

  5. Wer ist "Jia Tan"? Eine interessant zu lesende Spurensuche von
    @marcel anhand von technischen Indizien zu Zeitzonen, Verhalten, Motive, Aufwand.

    #XZBackdoor #ssh #opensource #dnip

    dnip.ch/2024/05/14/spurensuche

  6. Was wissen wir eigentlich über «Jia Tan»? Ich habe mich mal auf eine Spurensuche begeben. Und dabei herausgefunden, dass man mit der Sicherheitslücke wohl mehrere Milliarden hätte verdienen können.

    Ich nehme euch gerne mit auf diese Reise und die Schlussfolgerungen, die sich daraus ergeben.
    #JiaTan #xz #Backdoor #xzBackdoor #DNIP
    dnip.ch/2024/05/14/spurensuche

  7. @anneroth Mal davon ab dass ich dem #BND das technisch gar nicht wirklich zutraue. Wollen wir einen Geheimdienst der etwas die #xzbackdoor baut? Wohl kaum!

  8. BTW, if someone is thinking backdoors only exist in the #OpenSource software then this is not true. Finding such backdoors in Open Source software is easy because it is being reviewed by lots of researchers and programmers. Every PR is available for the world to see and verify. The closed source software could take years to find backdoors.

    #xz #xzBackdoor #security

  9. Thanks to an extra set of eyes we narrowly avoid the XZ backdoor spreading across the globe. 🪲🚪🌍

    Open source publishing is the most secure way to distribute code - That's why our client-side code is released transparently! ❤️🔐

    Read more here: tuta.com/blog/xz-linux-backdoo

    #xzbackdoor #opensource #tuta #privacymatters

  10. Diesen Donnerstag (2024-04-25) findet das nächste @engkiosk Meetup Alps in Innsbruck statt.

    engineeringkiosk.dev/meetup/al

    Unter anderem mit einem Vortrag zu #xzbackdoor von @rw.

  11. Elaastic on CVE-2024-3094 🔗 discuss.elastic.co/t/elastic-s

    On March 29th, 2024, Elastic became aware of the malicious code planted in the xz package. Elastic has performed an investigation to identify any Elastic Products which may be impacted by this issue and we have concluded that no Elastic products use the versions of xz affected by this vulnerability. Therefore, Elastic Products are not affected by this issue.

    #CVE_2024_3094 #xz #xzbackdoor #supplychainattack

  12. Nach XZ-Backdoor: Open-Source-Software als Risiko oder strategischer Vorteil? | heise online
    heise.de/-9692061 #xzUtils #xzBackdoor #OpenSource

  13. Im Kontext der #xzbackdoor sind die Messer gewetzt. Und in den Ring steigt der mir bisher unbekannte #DATABUND – Verband der mittelständischen IT-Dienstleister und Softwarehersteller für den öffentlichen Sektor e.V. mit seiner Pressemitteilung.

    #^OpenSource ist nicht die Lösung aller Probleme

    Ein Appetitanreger:
    Bereits in der Standardisierung wendet China diese Strategie seit über 10 Jahren an. Durch eine schiere Masse von Personen, die in die Gremien geworfen werden und die dann die Bildung von immer mehr Untergliederungen und Untergruppen vorantreiben, übernehmen sie in dem Moment die alleinige Steuerung, wo westliche Länder nicht mehr die Ressourcen haben, all diese Gremien zu besetzen. Im OpenSource-Bereich kann eine ähnliche Strategie genauso zum Erfolg führen und niemand kann sagen, ob sie nicht in einem oder mehreren anderen Fällen bereits erfolgreich gewesen ist. Die Kontrolle des Quellcodes funktioniert nur so lange, wie ausreichende Ressourcen für eine ausführliche und gewissenhafte Kontrolle vorhanden sind. Hinzu kommt, dass niemand die Verantwortung für Quellcode und dessen Kontrolle übernimmt. Fahrlässigkeit und Fehlverhalten haben keine wirtschaftlichen und juristischen Konsequenzen für einen Community-Entwickler. Keine öffentliche Verwaltung würde jedoch eine Software beschaffen, für die nicht die Funktionsfähigkeit garantiert und gehaftet wird.
  14. I was thinking specifically of the #xz Utils incident when I wrote this weeks column calling for an #opensource tax credit for developers.

    “A 2024 Harvard study valued [open source software] at $8.8 trillion.

    A software project may be initially undertaken by a single developer as a hobbyist project, but … maintenance and security updates require long-term commitments, often by an entire community of developers.”

    #xzbackdoor #floss #foss @floss @law #lawfedi

    news.bloomberglaw.com/tax-insi