Atemu@lemmy.ml to Linux@lemmy.ml · 1 year agobackdoor in upstream xz/liblzma leading to ssh server compromisewww.openwall.comexternal-linkmessage-square34linkfedilinkarrow-up132arrow-down10cross-posted to: selfhosted@lemmy.world
arrow-up132arrow-down1external-linkbackdoor in upstream xz/liblzma leading to ssh server compromisewww.openwall.comAtemu@lemmy.ml to Linux@lemmy.ml · 1 year agomessage-square34linkfedilinkcross-posted to: selfhosted@lemmy.world
minus-squarecapt_kafei@lemmy.calinkfedilinkEnglisharrow-up2·1 year agoDamn, it is actually scary that they managed to pull this off. The backdoor came from the second-largest contributor to xz too, not some random drive-by.
minus-squareAmbiguousProps@lemmy.todaylinkfedilinkEnglisharrow-up3·1 year agoThey’ve been contributing to xz for two years, and commited various “test” binary files.
minus-squareAlex@lemmy.mllinkfedilinkarrow-up2·1 year agoIt’s looking more like a long game to compromise an upstream.
minus-squarecjk@feddit.delinkfedilinkarrow-up1·1 year agoEither that or the attacker was very good at choosing their puppet…
minus-squarePossibly linux@lemmy.ziplinkfedilinkEnglisharrow-up0·1 year agoIt would be nice if we could press formal charges
minus-squaresim642@lemm.eelinkfedilinkarrow-up1·1 year agoAssuming that it’s just that person, that it’s their actual name and that they’re in the US…
minus-squarePossibly linux@lemmy.ziplinkfedilinkEnglisharrow-up0·1 year agoDo you have a source for this?
Damn, it is actually scary that they managed to pull this off. The backdoor came from the second-largest contributor to xz too, not some random drive-by.
They’ve been contributing to xz for two years, and commited various “test” binary files.
It’s looking more like a long game to compromise an upstream.
Either that or the attacker was very good at choosing their puppet…
It would be nice if we could press formal charges
Assuming that it’s just that person, that it’s their actual name and that they’re in the US…
deleted by creator
Do you have a source for this?
deleted by creator