home.social

#xzorcist — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #xzorcist, aggregated by home.social.

  1. Yay, #Debian reduces #OpenSSH dependencies (in Debian Unstable for now) and removes #libsystemd dependency.

    openssh (1:9.7p1-4) unstable; urgency=medium

    * Rework systemd readiness notification and socket activation patches to not link against libsystemd (the former via an upstream patch).
    * […]

    Thanks @cjwatson!

    (via tracker.debian.org/news/151654)

    #xz #xzbackdoor #xzorcist #JiaT75 #systemd #AttackSurfaceReduction

  2. Perhaps the long con is an even longer con in which an attacker attempts to drive many #infosec people into burnouts over time by hiding malware in packages that are then discovered just before holiday weekends.

    #xz #xzbackdoor #xzorcist #cve20243094

  3. There's A LOT going on (analysis, discussion, vendor notices, etc...) related to the ongoing xz/liblzma compromise so I created a "link roundup" which centralizes and buckets a lot of the awesome links and threads I've seen flying around.

    shellsharks.com/xz-compromise-

    I will *try* to keep this up-to-date (ish) for a few days while things are hot but I make no promises beyond that.

    #cve20243094 #xz #xzbackdoor #xzorcist #supplychainattack #xz4shell #infosec #cybersecurity

  4. @argv_minus_one

    Compliance Officers: „Maintainer, who does not owe me anything, I need you to fill out this form and take responsibility!“

    Salespeople: „My product solves this and any other problem in cybersecurity. With a premium sub you can also end world hunger.“

    LinkedIn Influencers: „The end is nigh! This time I’m sure!“

    #xzbackdoor #xz #xzorcist #cve20243094

  5. @Aaron: Oh, and the now infamous "Simplify SECURITY.md" commit by #JiaT75 is now also in that repo: git.tukaani.org/?p=xz.git;a=co

    So it's up to date with Github again (and now ahead of it). #xz #xzorcist #xzbackdoor

  6. @vaurora: In this case it was rather "not enough people involved" istead of "too many involved": See #busfactor and xkcd.com/2347 #xkcd2347

    This was only possible because the original maintainer did that work alone and seems to have been close to a #burnout and urgently needed someone to step in. So it was easy to get the co-maintainer position without long-time #trust being involved.

    #JiaT75 #xzorcist #xz #FLOSS

  7. @vaurora: In this case it was rather "not enough people involved" istead of "too many involved": See #busfactor and xkcd.com/2347 #xkcd2347

    This was only possible because the original maintainer did that work alone and seems to have been close to a #burnout and urgently needed someone to step in. So it was easy to get the co-maintainer position without long-time #trust being involved.

    #JiaT75 #xzorcist #xz #FLOSS

  8. @vaurora: In this case it was rather "not enough people involved" istead of "too many involved": See #busfactor and xkcd.com/2347 #xkcd2347

    This was only possible because the original maintainer did that work alone and seems to have been close to a #burnout and urgently needed someone to step in. So it was easy to get the co-maintainer position without long-time #trust being involved.

    #JiaT75 #xzorcist #xz #FLOSS