THE XZ UTILS BACKDOOR IS A STARK REMINDER THAT IF YOU RELY ON BITCOIN IT IS IMPERATIVE TO SUPPORT THE OPEN SOURCE CONTRIBUTORS THAT MAKE THIS MOVEMENT POSSIBLE.

GOOD MORNING.

https://www.wired.com/story/jia-tan-xz-backdoor/

Reply to this note

Please Login to reply.

Discussion

Slow burn. I was tasked with checking all of our systems to ensure the exploited version wasn’t in our farm.

As far as I know It’s a very specific attack. You need to run a distribution that is rolling release _and_ uses the binary tarball of XZ while having the SSH system notify thing on. Its almost specifically sorts out Debian testing derivatives and Fedora.

For example, Arch has the infected binary but its SSH is not linked to it. NixOS will have the 5.6.1 version but its clean because they’ve built from source instead of using the published binaries.

But if you have something important running on those servers that got touched by those exploits its better to just wipe clean and redeploy those machines.

Correct. Kali was another one. Fedora rawhide, a few opensuse as well. No Debian or RHEL release

GM. Bullish on xz compression, systemd, openssh and other fee software.

GOOD MORNING ☀️

🫡 GOOD MORNING

Paywalled. 😐

GM 🤠🤙 OPEN SOURCE EVERYTHING

Good morning ☕️

GM!

GM CHIEF 🫡

GM

GM☕

GM 🫡

GM great reminder

GM, wouldn't want to be a compliance officer for any major software company amirite

Good morning. Lots of love and respect for open source devs. This should be a no brainer. nostr:npub15dqlghlewk84wz3pkqqvzl2w2w36f97g89ljds8x6c094nlu02vqjllm5m what is your opinion on this?

GOOD MORNING. THIS IS A FRIENDLY REMINDER THAT nostr:npub15dqlghlewk84wz3pkqqvzl2w2w36f97g89ljds8x6c094nlu02vqjllm5m AND #MSTR RELY ON BITCOIN. 🫂💜🤙

GOOD MORNING (`・ω・´)ゞ⚡おはよう

Support open source contributors

Support open source contributors

nostr:note16xf4uc9y2y7ywkwwyefdp438dz7vcmp6cqsd8jzz6ud7prah80fqxz65gx

Damn right keep the pressure on Sayler. His pockets are deeper than mine.

And whatever he says people do and believe 🤷🏽‍♂️

the Amish have been warning us for years. why didn't we listen?! 👨‍🌾

SUPPORT THE AUTISTS

You know when a chat room is one to avoid when you post the above from @odell and everyone ignores you. #foss