Unfolding now: news.ycombinator.com/item?id=3

- openwall.com/lists/oss-securit
- github.com/tukaani-project/xz/

An incredibly technically complex in xz (potentially also in libarchive and elsewhere) was just discovered. This backdoor has been quietly implemented over years, with the assistance of a wide array of subtly interconnected accounts:

- github.com/tukaani-project/xz/
- bugs.debian.org/cgi-bin/bugrep
- github.com/jamespfennell/xz/pu

The timeline on this is going to take so long to unravel

1
Share
Share on Mastodon
Share on Twitter
Share on Facebook
Share on Linkedin
Replies