It's very illegal. iirc it was created by a group called "Pirate Library Mirror" after the guy that runs z-library got arrested, so I assume they're taking anonymity seriously to avoid arrest.
It's not though, because the malicious release happened more than two weeks ago and manjaro had to fast track the patched xs from arch git repo. This is why manjaro should extend their delayed update policy to catch this kind of issue in the future (maybe 2 months instead of 2 weeks) /s
What scary is the maintainer that insert the backdoor has been main maintainer for xz for the last two years. Who know if they have other backdoors inserted in the last 2 years? Investigation is still ongoing so I expect more juicy revelations in the next few days.
If you're using xz version 5.6.0 or 5.6.1, please upgrade asap, especially if you're using a rolling-release distro like Arch or its derivatives. Arch has rolled out the patched version a few hours ago.
I assume you're adding the blacklist into your host file? How big is your block file? I remember one think that finally pushed me to use pihole and adguard a few years ago was due to my large host file causing >1s dns lookup time. Moving to pihole improved performance significantly in my case. Not sure if OS these days can handle large host file without huge performance impact though.
Where I live, doctors are discouraged (though not forbidden) to treat themselves and their family because of increased risk of misdiagnose. For example, when treating their own kids, some people tend to worry too much when their children get some fever, which lead to over medication. On the other hand, some people tend to not worry too much and not treating their kids until it's too late.
"Bures" -- javanese