7 ms·
The xz-utils backdoor has been removed
- EveryPizza 2y agoThe security policy was also updated: https://github.com/tukaani-project/xz/commit/780d2c236de0e4749655696c2e0c26fb7565afd3 https://github.com/tukaani-project/xz/commit/780d2c236de0e47...
- throwiforgtnlzy 2y agoMaybe we need an international NGO/co-op to provide essential services for small, essential FOSS projects such as security comms, security audits, build infrastructure, testing, best practices, background investigations, and so forth. The "one guy's little piece of code holding up the world" is a SPOF and much easier to attack than if they had some help and automation.
- zoobab 2y ago"security comms, security audits, build infrastructure, testing, best practices, background investigations, and so forth." Typical over-engineering that comes from large corporations. They will turn FOSS into a walled garden, as if contributing to projects was not a pain already.
- mschuster91 2y ago> They will turn FOSS into a walled garden, as if contributing to projects was not a pain already. The only thing in here that has potential negative impact are the background investigations, but it might be reasonable to have an independent third party that offers this as a service for project leads.
- TillE 2y agoI'm relieved that the GitHub repo has finally been restored. I was just about to make a commit to fix our liblzma dependency, which would have required a vcpkg overlay to use a different upstream repo.
- rgovostes 2y agoThis commit message is gold: https://github.com/tukaani-project/xz/commit/e93e13c8b3bec925c56e0c0b675d8000a0f7f754 https://github.com/tukaani-project/xz/commit/e93e13c8b3bec92... While the backdoor was inactive (and thus harmless) without inserting a small trigger code into the build system when the source package was created, it's good to remove this anyway: - The executable payloads were embedded as binary blobs in the test files. This was a blatant violation of the Debian Free Software Guidelines. - On machines that see lots bots poking at the SSH port, the backdoor noticeably increased CPU load, resulting in degraded user experience and thus overwhelmingly negative user feedback. - The maintainer who added the backdoor has disappeared. - Backdoors are bad for security.
- syntheticcdo 2y agohttps://github.com/tukaani-project/xz/commit/780cbf29d5a88db2b546e9b7b019c4c33ca72685 https://github.com/tukaani-project/xz/commit/780cbf29d5a88db... to update the NEWS file is equally honest: 5.6.1 (2024-03-09) IMPORTANT: This fixed bugs in the backdoor (CVE-2024-3094) (someone had forgot to run Valgrind).
- glandium 2y agohttps://github.com/tukaani-project/xz/commit/77a294d98a9d2d48f7e4ac273711518bf689f5c4 https://github.com/tukaani-project/xz/commit/77a294d98a9d2d4... Special author: Jia Tan was a co-maintainer in 2022-2024. He and the team behind him inserted a backdoor (CVE-2024-3094) into XZ Utils 5.6.0 and 5.6.1 releases. He suddenly disappeared when this was discovered.
- usr1106 2y agoViolation of the Debian Free Software guidelines? Is that a problem? The owner of github became a money making machine using a business model violating the same guidelines.
- jwilk 2y agoIt was a joke.