Live data from Hacker News

The xz-utils backdoor has been removed

github.com

1–10 of 23 posts

Re: The xz-utils backdoor has been removed

#4
This commit message is gold: https://github.com/tukaani-project/xz/commit/e93e13c8b3bec92...

    While the backdoor was inactive (and thus harmless) without inserting
    a small trigger code into the build system when the source package was
    created, it's good to remove this anyway:

      - The executable payloads were embedded as binary blobs in
        the test files. This was a blatant violation of the
        Debian Free Software Guidelines.

      - On machines that see lots bots poking at the SSH port, the backdoor
        noticeably increased CPU load, resulting in degraded user experience
        and thus overwhelmingly negative user feedback.

      - The maintainer who added the backdoor has disappeared.

      - Backdoors are bad for security.

Re: The xz-utils backdoor has been removed

#5

This commit message is gold: https://github.com/tukaani-project/xz/commit/e93e13c8b3bec92... While the backdoor was inactive (and thus harmless) without inserting a small trigger code into the build system when the source package was created, it's good to remove this anyway: - The executable payloads were embedded as binary blobs in the test files. This was a blatant violation of the Debian Free Software Guidelines.…

https://github.com/tukaani-project/xz/commit/780cbf29d5a88db... to update the NEWS file is equally honest:

    5.6.1 (2024-03-09)

    IMPORTANT: This fixed bugs in the backdoor (CVE-2024-3094) (someone
    had forgot to run Valgrind).

Re: The xz-utils backdoor has been removed

#6

This commit message is gold: https://github.com/tukaani-project/xz/commit/e93e13c8b3bec92... While the backdoor was inactive (and thus harmless) without inserting a small trigger code into the build system when the source package was created, it's good to remove this anyway: - The executable payloads were embedded as binary blobs in the test files. This was a blatant violation of the Debian Free Software Guidelines.…

https://github.com/tukaani-project/xz/commit/77a294d98a9d2d4...

    Special author: Jia Tan was a co-maintainer in 2022-2024. He and
    the team behind him inserted a backdoor (CVE-2024-3094) into
    XZ Utils 5.6.0 and 5.6.1 releases. He suddenly disappeared when
    this was discovered.

Re: The xz-utils backdoor has been removed

#7

This commit message is gold: https://github.com/tukaani-project/xz/commit/e93e13c8b3bec92... While the backdoor was inactive (and thus harmless) without inserting a small trigger code into the build system when the source package was created, it's good to remove this anyway: - The executable payloads were embedded as binary blobs in the test files. This was a blatant violation of the Debian Free Software Guidelines.…

Violation of the Debian Free Software guidelines? Is that a problem?

The owner of github became a money making machine using a business model violating the same guidelines.

Re: The xz-utils backdoor has been removed

#8

The security policy was also updated: https://github.com/tukaani-project/xz/commit/780d2c236de0e47...

Maybe we need an international NGO/co-op to provide essential services for small, essential FOSS projects such as security comms, security audits, build infrastructure, testing, best practices, background investigations, and so forth.

The "one guy's little piece of code holding up the world" is a SPOF and much easier to attack than if they had some help and automation.

Re: The xz-utils backdoor has been removed

#9
post #7

This commit message is gold: https://github.com/tukaani-project/xz/commit/e93e13c8b3bec92... While the backdoor was inactive (and thus harmless) without inserting a small trigger code into the build system when the source package was created, it's good to remove this anyway: - The executable payloads were embedded as binary blobs in the test files. This was a blatant violation of the Debian Free Software Guidelines.…

Violation of the Debian Free Software guidelines? Is that a problem? The owner of github became a money making machine using a business model violating the same guidelines.

It was a joke.

Re: The xz-utils backdoor has been removed

#10

The security policy was also updated: https://github.com/tukaani-project/xz/commit/780d2c236de0e47...

Maybe we need an international NGO/co-op to provide essential services for small, essential FOSS projects such as security comms, security audits, build infrastructure, testing, best practices, background investigations, and so forth. The "one guy's little piece of code holding up the world" is a SPOF and much easier to attack than if they had some help and automation.

"security comms, security audits, build infrastructure, testing, best practices, background investigations, and so forth."

Typical over-engineering that comes from large corporations.

They will turn FOSS into a walled garden, as if contributing to projects was not a pain already.

Post reply on HN