This commit message is gold: https://github.com/tukaani-project/xz/commit/e93e13c8b3bec92... While the backdoor was inactive (and thus harmless) without inserting a small trigger code into the build system when the source package was created, it's good to remove this anyway: - The executable payloads were embedded as binary blobs in the test files. This was a blatant violation of the Debian Free Software Guidelines.…
The xz-utils backdoor has been removed
11–20 of 23 posts
Re: The xz-utils backdoor has been removed
#12This commit message is gold: https://github.com/tukaani-project/xz/commit/e93e13c8b3bec92... While the backdoor was inactive (and thus harmless) without inserting a small trigger code into the build system when the source package was created, it's good to remove this anyway: - The executable payloads were embedded as binary blobs in the test files. This was a blatant violation of the Debian Free Software Guidelines.…
Debian and NixOS (and other distros) are already downgrading or discussing to downgrade to versions without those commits.
I think that making a 5.4 or 5.6 release without any of those commits (with stuff reimplemented as needed) would assuage most concerns
Re: The xz-utils backdoor has been removed
#13This commit message is gold: https://github.com/tukaani-project/xz/commit/e93e13c8b3bec92... While the backdoor was inactive (and thus harmless) without inserting a small trigger code into the build system when the source package was created, it's good to remove this anyway: - The executable payloads were embedded as binary blobs in the test files. This was a blatant violation of the Debian Free Software Guidelines.…
It's really sad to see commit messages like this, downplaying the issue. It's also concerning to see libsystemd get a free pass.
Re: The xz-utils backdoor has been removed
#14This commit message is gold: https://github.com/tukaani-project/xz/commit/e93e13c8b3bec92... While the backdoor was inactive (and thus harmless) without inserting a small trigger code into the build system when the source package was created, it's good to remove this anyway: - The executable payloads were embedded as binary blobs in the test files. This was a blatant violation of the Debian Free Software Guidelines.…
I would really really really like to see all commits by Jia Tan reverted, not only those currently found to be malicious. Debian and NixOS (and other distros) are already downgrading or discussing to downgrade to versions without those commits. I think that making a 5.4 or 5.6 release without any of those commits (with stuff reimplemented as needed) would assuage most concerns
Re: The xz-utils backdoor has been removed
#15This commit message is gold: https://github.com/tukaani-project/xz/commit/e93e13c8b3bec92... While the backdoor was inactive (and thus harmless) without inserting a small trigger code into the build system when the source package was created, it's good to remove this anyway: - The executable payloads were embedded as binary blobs in the test files. This was a blatant violation of the Debian Free Software Guidelines.…
> This commit message is gold It's really sad to see commit messages like this, downplaying the issue. It's also concerning to see libsystemd get a free pass.
Re: The xz-utils backdoor has been removed
#16Earlier quoted context omitted.
I would really really really like to see all commits by Jia Tan reverted, not only those currently found to be malicious. Debian and NixOS (and other distros) are already downgrading or discussing to downgrade to versions without those commits. I think that making a 5.4 or 5.6 release without any of those commits (with stuff reimplemented as needed) would assuage most concerns
Who would do that? The project lacking active contributors is what enabled Jai Tan to get away with it in the first place.
Re: The xz-utils backdoor has been removed
#17Earlier quoted context omitted.
Who would do that? The project lacking active contributors is what enabled Jai Tan to get away with it in the first place.
Can’t we migrate to other libraries?
Re: The xz-utils backdoor has been removed
#18Earlier quoted context omitted.
Maybe we need an international NGO/co-op to provide essential services for small, essential FOSS projects such as security comms, security audits, build infrastructure, testing, best practices, background investigations, and so forth. The "one guy's little piece of code holding up the world" is a SPOF and much easier to attack than if they had some help and automation.
"security comms, security audits, build infrastructure, testing, best practices, background investigations, and so forth." Typical over-engineering that comes from large corporations. They will turn FOSS into a walled garden, as if contributing to projects was not a pain already.
The only thing in here that has potential negative impact are the background investigations, but it might be reasonable to have an independent third party that offers this as a service for project leads.
Re: The xz-utils backdoor has been removed
#19This commit message is gold: https://github.com/tukaani-project/xz/commit/e93e13c8b3bec92... While the backdoor was inactive (and thus harmless) without inserting a small trigger code into the build system when the source package was created, it's good to remove this anyway: - The executable payloads were embedded as binary blobs in the test files. This was a blatant violation of the Debian Free Software Guidelines.…
> This commit message is gold It's really sad to see commit messages like this, downplaying the issue. It's also concerning to see libsystemd get a free pass.
Re: The xz-utils backdoor has been removed
#20Earlier quoted context omitted.
> This commit message is gold It's really sad to see commit messages like this, downplaying the issue. It's also concerning to see libsystemd get a free pass.
How did they get a free pass?
Which is what enabled this vulnerability to be viable.