#xzbackdoor — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #xzbackdoor, aggregated by home.social.
-
Half a Second – a book about the XZ backdoor
Comments: https://news.ycombinator.com/item?id=48966139
#HackerNews #HalfASec #XZBackdoor #Cybersecurity #Book #TechNews #HackerNews
-
I had to deal a bit with the "Supply-chain Levels for Software Artifacts" (SLSA) "standard":
https://slsa.dev/IMO it's a joke, since they do not properly deal with threats from "Includ[ing] a vulnerable dependency (library, base image, bundled file, etc.)". They essentially say "A future version of this standard might deal with that":
https://slsa.dev/spec/v1.2/threatsThis has been the main entry point of the past supply chain attacks (XZ backdoor, litellm, Shai-Hulud, ...). A supply-chain security standard that doesn't properly deal with vulnerabilities in dependencies completely misses the point. It's like installing alarms on your windows (to catch burglars trying to enter your home through the windows) when your front door doesn't have a lock.
#SLSA #supplychain #supplychainsecurity #xzbackdoor #ShaiHulud #litellm
-
Could the XZ backdoor have been detected with better Git and Debian packaging practices?
#XZBackdoor
https://optimizedbyotto.com/post/xz-backdoor-debian-git-detection/ -
📬 Supply-Chain-Angriff: NPM-Pakete mit 2,6 Milliarden Downloads pro Woche infiziert
#Cyberangriffe #ITSicherheit #Malware #Softwareentwicklung #chalk #Cybersicherheit #debug #javascript #Kryptowährung #NPM #Phishing #Sicherheit #SupplyChainAngriff #XZBackdoor https://sc.tarnkappe.info/7a32db -
https://liblzma.so/ I made a thing. impulse control is for suckers
-
@mike One one hand, governments and corporations shouldn't have to pay for using open-source software since it is explicitly provided Free....
On the other hand, it's not really fair when some poor maintainer finds themselves maintaining a project that a lot of people really depend on (the #XZbackdoor comes to mind). -
Lasse Collin (the developer of xz-utils) has found out how to accept donations without breaking the Finnish money collection law:
https://github.com/tukaani-project/xz/issues/105#issuecomment-2599004098He has created an account on #LiberaPay with a restriction to not accept donations from Finns or people living in Finland:
https://liberapay.com/Larhzu/ -
I thought the case of the #xzbackdoor would be a really good way to make students aware of the many different dimensions of computing, and the “The Philosophy of the Open Source Pledge” https://vladh.net/the-philosophy-of-the-open-source-pledge/, which I assigned as reading, highlights many of the issues in a concise fashion.
Most students: 😴
-
NPR Podcast about the recent XZ backdoor hack that came close to breaking the internet: https://www.npr.org/2024/05/17/1197959102/open-source-xz-hack
#opensource #XZ #XZHack #npr #podcast #podcasts #hack #hacking #CyberSecurityAwareness #CyberSecurity #opsec #supplychainattack #software #linux #unix #debian #RHEL #RedHat #hacker #hackers #PlanetMoney #backdoor #xzbackdoor
-
Wer ist "Jia Tan"? Eine interessant zu lesende Spurensuche von
@marcel anhand von technischen Indizien zu Zeitzonen, Verhalten, Motive, Aufwand. -
Was wissen wir eigentlich über «Jia Tan»? Ich habe mich mal auf eine Spurensuche begeben. Und dabei herausgefunden, dass man mit der Sicherheitslücke wohl mehrere Milliarden hätte verdienen können.
Ich nehme euch gerne mit auf diese Reise und die Schlussfolgerungen, die sich daraus ergeben.
#JiaTan #xz #Backdoor #xzBackdoor #DNIP
https://dnip.ch/2024/05/14/spurensuche-jia-tan-xz/ -
@anneroth Mal davon ab dass ich dem #BND das technisch gar nicht wirklich zutraue. Wollen wir einen Geheimdienst der etwas die #xzbackdoor baut? Wohl kaum!
-
BTW, if someone is thinking backdoors only exist in the #OpenSource software then this is not true. Finding such backdoors in Open Source software is easy because it is being reviewed by lots of researchers and programmers. Every PR is available for the world to see and verify. The closed source software could take years to find backdoors.
-
Thanks to an extra set of eyes we narrowly avoid the XZ backdoor spreading across the globe. 🪲🚪🌍
Open source publishing is the most secure way to distribute code - That's why our client-side code is released transparently! ❤️🔐
Read more here: https://tuta.com/blog/xz-linux-backdoor -
Diesen Donnerstag (2024-04-25) findet das nächste @engkiosk Meetup Alps in Innsbruck statt.
https://engineeringkiosk.dev/meetup/alps/
Unter anderem mit einem Vortrag zu #xzbackdoor von @rw.
-
Elaastic on CVE-2024-3094 🔗 https://discuss.elastic.co/t/elastic-security-statement-for-cve-2024-3094-xz-versions-5-6-0-and-5-6-1/357894
On March 29th, 2024, Elastic became aware of the malicious code planted in the xz package. Elastic has performed an investigation to identify any Elastic Products which may be impacted by this issue and we have concluded that no Elastic products use the versions of xz affected by this vulnerability. Therefore, Elastic Products are not affected by this issue.
-
Nach XZ-Backdoor: Open-Source-Software als Risiko oder strategischer Vorteil? | heise online
https://heise.de/-9692061 #xzUtils #xzBackdoor #OpenSource -
Im Kontext der #xzbackdoor sind die Messer gewetzt. Und in den Ring steigt der mir bisher unbekannte #DATABUND – Verband der mittelständischen IT-Dienstleister und Softwarehersteller für den öffentlichen Sektor e.V. mit seiner Pressemitteilung.
#^OpenSource ist nicht die Lösung aller Probleme
Ein Appetitanreger:Bereits in der Standardisierung wendet China diese Strategie seit über 10 Jahren an. Durch eine schiere Masse von Personen, die in die Gremien geworfen werden und die dann die Bildung von immer mehr Untergliederungen und Untergruppen vorantreiben, übernehmen sie in dem Moment die alleinige Steuerung, wo westliche Länder nicht mehr die Ressourcen haben, all diese Gremien zu besetzen. Im OpenSource-Bereich kann eine ähnliche Strategie genauso zum Erfolg führen und niemand kann sagen, ob sie nicht in einem oder mehreren anderen Fällen bereits erfolgreich gewesen ist. Die Kontrolle des Quellcodes funktioniert nur so lange, wie ausreichende Ressourcen für eine ausführliche und gewissenhafte Kontrolle vorhanden sind. Hinzu kommt, dass niemand die Verantwortung für Quellcode und dessen Kontrolle übernimmt. Fahrlässigkeit und Fehlverhalten haben keine wirtschaftlichen und juristischen Konsequenzen für einen Community-Entwickler. Keine öffentliche Verwaltung würde jedoch eine Software beschaffen, für die nicht die Funktionsfähigkeit garantiert und gehaftet wird.
-
I was thinking specifically of the #xz Utils incident when I wrote this weeks column calling for an #opensource tax credit for developers.
“A 2024 Harvard study valued [open source software] at $8.8 trillion.
A software project may be initially undertaken by a single developer as a hobbyist project, but … maintenance and security updates require long-term commitments, often by an entire community of developers.”
-
Back door xz vulnerability has been officially reverted for @fedora 40 https://www.linux-magazine.com/Online/News/XZ-Gets-the-All-Clear #malare #XZBackdoor #Fedora #Ubuntu #ArchLinux #Linux #OpenSource #security #patch #Rawhide #FOSS