Skip Navigation
Jump
XZ backdoor in a nutshell
  • A whitelisting application has a list of what it knows it bad AND what it knows in advance to be good.

    How would it know this? Is this defined by a person/people? If so, that wouldn't have mattered. liblzma was known in advance to be good, then the malicious update was added, and people still presumed that it was good.

    This wasn't a case of some random package/program wreaking havoc. It was trusted malicious code.

    Also, you're asking for an antivirus that uploads and uses a sandbox to analyze ALL packages. Good luck with that. (AVs would probably have a hard time detecting malicious build actions, anyways).

    2
  • Jump
    Smart devices are turning out to be a poor investment
  • This is why I only buy shitty cheap chinese IoT devices. Less likely that they're going to enshittify my devices for profit. Maybe use VLANs and a firewall, though.

    1
  • Jump
    What we know about the xz Utils backdoor that almost infected the world
  • It's crazy how they pressured/manipulated the maintainer. Especially fucked up considering he wasn't in a good mental state and was still helping the community by maintaining FOSS software.

    8
  • Jump
    Is TypeScript a fad or is my manager delusional?
  • What's the point of calling something a "fad"? If the technology works well and it provides value to you, why should you care what other people think?

    (Example: Look at PHP)

    13