Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
ui2RjUen875bfFA
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
3 ms
·
1.
▲
by
ui2RjUen875bfFA
3y ago
i guess the big opensource community should put a little bit more trust in statistics or integrate statistic evaluation in their decission making to use specific products in their supply chains. there are some researches on the right track
2.
▲
by
ui2RjUen875bfFA
3y ago
i added there something about a possible planned kernel attack which not mentioned so much yet. https://gist.github.com/thesamesam/223949d5a074ebc3dce9ee78b...
3.
▲
by
ui2RjUen875bfFA
3y ago
> Arch Linux played an important role in making this compression software trusted and depended upon. because of the way arch distributes packages? then what you think about freebsd?
4.
▲
by
ui2RjUen875bfFA
3y ago
You might read https://www.openwall.com/lists/oss-security/2024/03/29/4 "However, building from source wouldn’t have protected you against this specific backdoor." Depends on how exactly y
5.
▲
by
ui2RjUen875bfFA
3y ago
just take a closer look at the analysis https://www.openwall.com/lists/oss-security/2024/03/29/4 then try to understand the pattern. they backdoored by modifying the build process of packages. now c
6.
▲
by
ui2RjUen875bfFA
3y ago
those pipe usages are quite suspicious https://git.kernel.org/pub/scm/linux/kernel/git/next/linux-n... https://git.kernel.org/pub/scm/linux/kernel/git/n