GM #nostr ☕️🌞

the xz utils attack should be a wake-up call for all open source projects. an attack was planned here over a long period of time.

Reply to this note

Please Login to reply.

Discussion

GM ☕☀️🎨

Everyone called it a back door, while it was a supply chain attack.

exactly, you get to the point

What happened 👀?

in my opinion a supply chain attack on open ssh over xz.

https://nvd.nist.gov/vuln/detail/CVE-2024-3094

This time it was discovered (by accident), but how often has it worked or will it work?

What is the alternative? Telnet over wireguard?

it's more about how to deal with dependencies in projects and how to support small contributors and their work

It would be nice having an alternative nonetheless. Just curious if anyone thought of this before.

Never underestimate a bad actors patience.

GM ☀️☀️

🫂

Good morning ☀️

🌞