>Our no-longer-reasonable requestor also offers a suggestions. Notice there is no offer to actually help. Help in maintainship how? Patches had already been made and were awaiting to be reviewed and merged. This was up to the maintainer to do and requestor couldn't help with it.
> Help in maintainship how? Pay.
Xz: A microcosm of the interactions in open source projects
11–20 of 353 posts
Re: Xz: A microcosm of the interactions in open source projects
#12So the first step of this huge mess was: a social engineering attack. Attacking a tired, burnt-out open source project developer and peer pressuring him into giving more control of the repo to the attacker.
Re: Xz: A microcosm of the interactions in open source projects
#13Funny. I was just saying the same thing to one of my partners just 4 hours ago. Culpability also must be laid at RedHat's feet for sanctioning the practice of side loading libraries into such a critical service's address space. Their drive to cellularize systems management has overtaken their common sense. The idea that they could not be bothered to answer the call of the sole maintainer of a library used in such a c…
1) Debian includes this downstream patch, also. 2) A potential explanation for "why now" is that systemd DID prevent these dependencies from loading automatically in a patch one month ago [0], and the patches to lzma enabling the backdoor merged a few days later, followed by (as we know) an immediate and somewhat heavy push to get distros to upgrade driven by sockpuppets. It could be a total coincidence, or it could…
Choosing a distro is nothing but choosing where you place your trust.
I can understand debian cutting corners here and there. But RH have little excuses with the money they make. Yet, even a superficial analysis, show them to be less trustworthy than the anime-avatars maintaining gentoo or arch.
Re: Xz: A microcosm of the interactions in open source projects
#14So the first step of this huge mess was: a social engineering attack. Attacking a tired, burnt-out open source project developer and peer pressuring him into giving more control of the repo to the attacker.
Enabled by customers who don’t pay or donate.
Re: Xz: A microcosm of the interactions in open source projects
#15So the first step of this huge mess was: a social engineering attack. Attacking a tired, burnt-out open source project developer and peer pressuring him into giving more control of the repo to the attacker.
Re: Xz: A microcosm of the interactions in open source projects
#16Re: Xz: A microcosm of the interactions in open source projects
#17So the first step of this huge mess was: a social engineering attack. Attacking a tired, burnt-out open source project developer and peer pressuring him into giving more control of the repo to the attacker.
Re: Xz: A microcosm of the interactions in open source projects
#18>Our no-longer-reasonable requestor also offers a suggestions. Notice there is no offer to actually help. Help in maintainship how? Patches had already been made and were awaiting to be reviewed and merged. This was up to the maintainer to do and requestor couldn't help with it.
> Help in maintainship how? Pay.
At the same time, this attempt nicely illustrated that the chain is only as strong as the weakest link since, as I understand it, no part of the backdoor was committed to the git repository in cleartext. Instead, the part of the backdoor that was at least somewhat identifiable was only included in the tarballs that would be downloaded and used by Debian/Fedora when building the packages for these distributions, thus giving a very nice trade-off between the chance of someone detecting what was going on and the potential impact of the backdoor.
Re: Xz: A microcosm of the interactions in open source projects
#19At which point if “the community” consists of one guy doing everything and a couple whiners making demands, fuck it.