β² 472 βΌ Arch with XZ (lemmy.world) submitted 2 years ago by qwioeue@lemmy.world to c/linuxmemes@lemmy.world 89 comments fedilink hide all child comments
[β] A_Very_Big_Fan@lemmy.world 3 points 2 years ago (2 children) instead of the tarballs that did have the manipulations in them My only exposure to Linux is SteamOS so I might be misunderstanding something, but if not: How in the world did it get infected in the first place? Do we know? permalink fedilink source parent hideshow 4 child comments replies: [β] khannie@lemmy.world 8 points 2 years ago (1 child) From what I read it was one of the contributors. Looks like they have been contributing for some time too before trying to scooch in this back door. Long con. permalink fedilink source parent hideshow 2 child comments replies: [β] dan@upvote.au 9 points 2 years ago (1 child) It seems like this contributor had malicious intent the entire time they worked on the project. https://boehs.org/node/everything-i-know-about-the-xz-backdoor permalink fedilink source parent hideshow 2 child comments replies: [β] khannie@lemmy.world 3 points 2 years ago* (last edited 2 years ago) Wow. That is some read. edit:I keep thinking my jaw can't go any closer to the floor but I keep reading and my jaw keeps dropping. HOLY COW! permalink fedilink source parent [β] HopFlop@discuss.tchncs.de 4 points 2 years ago Basically, one of the contributors that had been contributing for quite some time (and was therefore partly trusted), commited a somewhat hidden backdoor. I doubt it had any effect (as it was discovered now before being pushed to any stable distro and the exploit itself didnt work on Arch) bjt we'll have to wait for the effect to be analyzed. permalink fedilink source parent
[β] khannie@lemmy.world 8 points 2 years ago (1 child) From what I read it was one of the contributors. Looks like they have been contributing for some time too before trying to scooch in this back door. Long con. permalink fedilink source parent hideshow 2 child comments replies: [β] dan@upvote.au 9 points 2 years ago (1 child) It seems like this contributor had malicious intent the entire time they worked on the project. https://boehs.org/node/everything-i-know-about-the-xz-backdoor permalink fedilink source parent hideshow 2 child comments replies: [β] khannie@lemmy.world 3 points 2 years ago* (last edited 2 years ago) Wow. That is some read. edit:I keep thinking my jaw can't go any closer to the floor but I keep reading and my jaw keeps dropping. HOLY COW! permalink fedilink source parent
[β] dan@upvote.au 9 points 2 years ago (1 child) It seems like this contributor had malicious intent the entire time they worked on the project. https://boehs.org/node/everything-i-know-about-the-xz-backdoor permalink fedilink source parent hideshow 2 child comments replies: [β] khannie@lemmy.world 3 points 2 years ago* (last edited 2 years ago) Wow. That is some read. edit:I keep thinking my jaw can't go any closer to the floor but I keep reading and my jaw keeps dropping. HOLY COW! permalink fedilink source parent
[β] khannie@lemmy.world 3 points 2 years ago* (last edited 2 years ago) Wow. That is some read. edit:I keep thinking my jaw can't go any closer to the floor but I keep reading and my jaw keeps dropping. HOLY COW! permalink fedilink source parent
[β] HopFlop@discuss.tchncs.de 4 points 2 years ago Basically, one of the contributors that had been contributing for quite some time (and was therefore partly trusted), commited a somewhat hidden backdoor. I doubt it had any effect (as it was discovered now before being pushed to any stable distro and the exploit itself didnt work on Arch) bjt we'll have to wait for the effect to be analyzed. permalink fedilink source parent