this post was submitted on 01 Apr 2024
3 points (100.0% liked)

Linux

48331 readers
372 users here now

From Wikipedia, the free encyclopedia

Linux is a family of open source Unix-like operating systems based on the Linux kernel, an operating system kernel first released on September 17, 1991 by Linus Torvalds. Linux is typically packaged in a Linux distribution (or distro for short).

Distributions include the Linux kernel and supporting system software and libraries, many of which are provided by the GNU Project. Many Linux distributions use the word "Linux" in their name, but the Free Software Foundation uses the name GNU/Linux to emphasize the importance of GNU software, causing some controversy.

Rules

Related Communities

Community icon by Alpár-Etele Méder, licensed under CC BY 3.0

founded 5 years ago
MODERATORS
 
top 22 comments
sorted by: hot top controversial new old
[–] Aatube@kbin.melroy.org 1 points 7 months ago (1 children)

Don't forget all of this was discovered because ssh was running 0.5 seconds slower

[–] possiblylinux127@lemmy.zip 0 points 7 months ago (1 children)

Postgres sort of saved the day

[–] Hupf@feddit.de 0 points 7 months ago

RIP Simon Riggs

[–] uis@lemm.ee 1 points 7 months ago
[–] Farnsworth@lemmy.world 0 points 7 months ago (1 children)

The tukaani github repos are gone, is there a mirror somewhere?

[–] fluxion@lemmy.world 0 points 7 months ago (1 children)
[–] TheFadingOne@feddit.de 0 points 7 months ago* (last edited 7 months ago)

Though unfortunately (or I guess for most use-cases fortunately) you can't find the malicious m4/build-to-host.m4 file on there afaik. The best way to find that now, should you really want to, is by looking through the commit history of the salsa.debian.org/debian/xz-utils repository which is, as far as I understand it, the repository that the debian packages are built from and consequently also what the compromised packages were built from.

[–] FatTony@lemm.ee 0 points 7 months ago (1 children)
[–] alphafalcon@feddit.de 0 points 7 months ago

Coconut at least...

[–] UnityDevice@startrek.website 0 points 7 months ago (1 children)

If this was done by multiple people, I'm sure the person that designed this delivery mechanism is really annoyed with the person that made the sloppy payload, since that made it all get detected right away.

[–] fluxion@lemmy.world 0 points 7 months ago (1 children)

I hope they are all extremely annoyed and frustrated

[–] acockworkorange@mander.xyz 0 points 7 months ago (1 children)
[–] Hupf@feddit.de 0 points 7 months ago

Inconceivable!

[–] Pantherina@feddit.de 0 points 7 months ago
[–] gregorum@lemm.ee 0 points 7 months ago (1 children)

Thank you open source for the transparency.

[–] Cornelius_Wangenheim@lemmy.world 0 points 7 months ago (1 children)
[–] Pantherina@feddit.de 0 points 7 months ago

They just pay some dude that is doing good work

[–] refreeze@lemmy.world 0 points 7 months ago (1 children)

I have been reading about this since the news broke and still can't fully wrap my head around how it works. What an impressive level of sophistication.

[–] rockSlayer@lemmy.world 0 points 7 months ago* (last edited 7 months ago) (1 children)

And due to open source, it was still caught within a month. Nothing could ever convince me more than that how secure FOSS can be.

[–] lung@lemmy.world 0 points 7 months ago

Idk if that's the right takeaway, more like 'oh shit there's probably many of these long con contributors out there, and we just happened to catch this one because it was a little sloppy due to the 0.5s thing'

This shit got merged. Binary blobs and hex digit replacements. Into low level code that many things use. Just imagine how often there's no oversight at all

[–] etchinghillside@reddthat.com 0 points 7 months ago (1 children)

Any additional information been found on the user?

[–] underisk@lemmy.ml 0 points 7 months ago* (last edited 7 months ago)

as long as you're up to date on everything here: https://boehs.org/node/everything-i-know-about-the-xz-backdoor

the only additional thing i've seen noted is a possibilty that they were using Arch based on investigation of the tarball that they provided to distro maintainers