#xzorcist

Neal Gompa (ニール・ゴンパ) :fedora:Conan_Kudo@fosstodon.org
2024-06-27

At #oSC24, the @SUSE security team gives a report about #xzorcist.

Xz backdoor talk by SUSE security team
stdevel @ #oSC2025stdevel@chaos.social
2024-04-26

Der April war vor allem von der #XZ-Lücke geprägt, die mir neben eurem Feedback besprechen. Es gab aber auch Erfreuliches: eine neue Forgejo-Vorabversion, neue #RHEL und #AlmaLinux Betas, sowie erste Entwicklungen der #Redis-Forks. Incus 6.0 LTS ist erschienen, Xen-Kosten scheinen sich zu erhöhen und Canonical bietet fortan bis zu 12 Jahre Support für LTS-Versionen, beginnend ab Ubuntu 14.04.

🎧 focusonlinux.podigee.io/103-ne

#XZorcist #FocusOnLinux #Podcast

Ein Mensch, beschriftet mit "Admin returning from the weekend", betritt eine Wohnung. In dieser brennt es - ein Mensch (beschriftet mit "Unstable software in production") hat einen Flammenwerfer in der Hand, zwei Menschen knien am Boden (beschriftet mit "Backdoof"), eine weitere Person (beschriftet mit "Opsec") versteckt sich hinter Möbeln und der brennende Boden ist mit "liblzma" beschriftet.
Campbell Jonesserebit@floss.social
2024-04-10

Any drama in #foss is just an opportunity for every developer with a blog site to get up on their soapbox and tell you what the problem REALLY is. Can't count how many of those I saw from #xzorcist.

@leachimus Da fällt mir doch fast das Mobile aus der Hand und weiß nicht, ich laut lachen oder heulen soll…
Aber hey, EIN #DEUTSCHER!!!!!11elf das wichtigste an der ganzen Sache….
#Drecksblatt #HaltDieFresseSpringerPresse
#xz #xzbackdoor #xzutils

Hihi: Aber der Hashtag ist wirklich witzig in dem (eigentlichen) Zusammenhang: #xzorcist 😂

Axel ⌨🐧🐪🚴😷 | R.I.P Natenomxtaran@chaos.social
2024-04-04

Yay, #Debian reduces #OpenSSH dependencies (in Debian Unstable for now) and removes #libsystemd dependency.

openssh (1:9.7p1-4) unstable; urgency=medium

* Rework systemd readiness notification and socket activation patches to not link against libsystemd (the former via an upstream patch).
* […]

Thanks @cjwatson!

(via tracker.debian.org/news/151654)

#xz #xzbackdoor #xzorcist #JiaT75 #systemd #AttackSurfaceReduction

2024-04-04

reflections on distrusting xz

"Was the ssh backdoor the only goal that "Jia Tan" was pursuing with their multi-year operation against xz?

I doubt it, and if not, then every fix so far has been incomplete, because everything is still running code written by that entity."
joeyh.name/blog/entry/reflecti
#xz #XzBackdoor #xzorcist #cve_2024_3094

Michel Lind :fedora: :debian:michelin@hachyderm.io
2024-04-01

@AndresFreundTec now that @fedora, @ubuntu and @archlinux have frame pointers, maybe this #xzorcist issue will encourage #Debian to follow suit

Axel ⌨🐧🐪🚴😷 | R.I.P Natenomxtaran@chaos.social
2024-04-01

Trying to take part in #30DaysOfBiking. Discovered it only today after dinner. Thanks to @ascentale for making me aware of it and @kimu + @IPEdmonton for explaining what it is and linking to 30daysofbiking.com/.

Originally I planned to do a cycle tour or two over the long Easter weekend, but then the #xzbackdoor fuckup happened and I sat hours in front of my workstation at home or the laptop. So in the end I did a short ride around the block today.

#xzorcist #xz #BikeTooter #BikeStreak

2024-04-01

Perhaps the long con is an even longer con in which an attacker attempts to drive many #infosec people into burnouts over time by hiding malware in packages that are then discovered just before holiday weekends.

#xz #xzbackdoor #xzorcist #cve20243094

2024-04-01

@tj @djm Further to this toot... Is there a known tip-jar / donation site for Lasse, the maintainer of xz?
#xz #xzbackdoor #xzutils #xzorcist

Neal Gompa (ニール・ゴンパ) :fedora:Conan_Kudo@fosstodon.org
2024-04-01

All this talk about #xzorcist over the weekend, I want to also point out that it's important to remember that the "software supply chain" largely does *not* exist in regards to open source, because most people have no real relationship other than parasitic consumption with the project.

@Di4na's great blog post on this topic explains it quite well: softwaremaxims.com/blog/not-a-

Patrick Schmidtpatrick@norden.social
2024-03-31

Wünsche Euch frohe Feiertage, ohne solche faulen Eier :blobcatpolicepeek:

Damit keine Panik ausbricht, Der #xzorcist getaufte #cve20243094 der Versionen xz 5.6.x erlaubt ssh RCE über den RSA Key 😰

ABER

"In stabile Debian- oder Ubuntu-Versionen hat die Hintertür es nicht geschafft, ...
Der macOS-Paketmanager Homebrew hingegen ist nicht direkt betroffen."

Termux/Gentoo Pakete bitte updaten.

social.heise.de/@heisec/112186

#xz #xzbackdoor #supplychainattack #xz4shell #infosec #cybersecurity

2024-03-31

There's A LOT going on (analysis, discussion, vendor notices, etc...) related to the ongoing xz/liblzma compromise so I created a "link roundup" which centralizes and buckets a lot of the awesome links and threads I've seen flying around.

shellsharks.com/xz-compromise-

I will *try* to keep this up-to-date (ish) for a few days while things are hot but I make no promises beyond that.

#cve20243094 #xz #xzbackdoor #xzorcist #supplychainattack #xz4shell #infosec #cybersecurity

2024-03-31

@argv_minus_one

Compliance Officers: „Maintainer, who does not owe me anything, I need you to fill out this form and take responsibility!“

Salespeople: „My product solves this and any other problem in cybersecurity. With a premium sub you can also end world hunger.“

LinkedIn Influencers: „The end is nigh! This time I’m sure!“

#xzbackdoor #xz #xzorcist #cve20243094

Justin Wheeler :fedora:jwf@floss.social
2024-03-31

Most of my feed on the #xzorcist #xz mess is solution-eering on ideas for paying maintainers. It implies the way to fix this is to simply pay people for their time.

I am not seeing something else though. Has anyone actually *asked* the maintainer what they want? What if that answer was not money? What if it was "I don't want to do this anymore?"

Regardless of the answer this time around, we should be prepared to boldly face these types of answers too.

#Linux #OpenSource #infosec #CVE20243094

mkbmkb
2024-03-31

OK, peeps, what’s the over/under on the number of days before another vuln with the same M.O. as is found?

And what about attribution? Place your bets!

Axel ⌨🐧🐪🚴😷 | R.I.P Natenomxtaran@chaos.social
2024-03-30

@Aaron: Oh, and the now infamous "Simplify SECURITY.md" commit by #JiaT75 is now also in that repo: git.tukaani.org/?p=xz.git;a=co

So it's up to date with Github again (and now ahead of it). #xz #xzorcist #xzbackdoor

Axel ⌨🐧🐪🚴😷 | R.I.P Natenomxtaran@chaos.social
2024-03-30

@vaurora: In this case it was rather "not enough people involved" istead of "too many involved": See #busfactor and xkcd.com/2347 #xkcd2347

This was only possible because the original maintainer did that work alone and seems to have been close to a #burnout and urgently needed someone to step in. So it was easy to get the co-maintainer position without long-time #trust being involved.

#JiaT75 #xzorcist #xz #FLOSS

Client Info

Server: https://mastodon.social
Version: 2025.04
Repository: https://github.com/cyevgeniy/lmst