Toast Dog Lemmy
  • Communities
  • Create Post
  • Create Community
  • heart
    Support Lemmy
  • search
    Search
  • Login
  • Sign Up
HayadSont@discuss.online to Linux@programming.devEnglish ·
edit-2
1 month ago

XZ Utils Back Door in Linux - Analysis of the Attack

www.youtube.com

external-link
message-square
3
link
fedilink
44
external-link

XZ Utils Back Door in Linux - Analysis of the Attack

www.youtube.com

HayadSont@discuss.online to Linux@programming.devEnglish ·
edit-2
1 month ago
message-square
3
link
fedilink
The XZ Utils Linux Hack: A Supply Chain Attack
www.youtube.com
external-link
XZ back door hack in Linux was found exploiting SSH with liblzma but was is the aftermath? Linux Distros like Fedora, Red hat, Ubuntu, Debian, Arch Linux wer...

A video by SavvyNik that covers some of the highlights from the following recently published scientific article - Wolves in the Repository: A Software Engineering Analysis of the XZ Utils Supply Chain Attack

alert-triangle
You must log in or register to comment.
  • HayadSont@discuss.onlineOP
    link
    fedilink
    arrow-up
    1
    ·
    edit-2
    5 minutes ago

    deleted by creator

  • jia_tan@lemmy.blahaj.zone
    link
    fedilink
    English
    arrow-up
    11
    ·
    1 month ago

    Pretty good breakdown. Glad to see my hard work recognized!

  • w3dd1e@lemm.ee
    link
    fedilink
    arrow-up
    5
    ·
    1 month ago

    Thanks for posting. I was literally l looking for updates on this recently and couldn’t find anything. I was worried that it might have been forgotten about

    • HayadSont@discuss.onlineOP
      link
      fedilink
      arrow-up
      3
      ·
      1 month ago

      Thanks for posting.

      It has been my pleasure!

      I was worried that it might have been forgotten about

      The XZ utils supply chain attack has actually made the community more wary of blobs. Some projects were even prompted to come clean on this matter.

      Fedora has also recently made a push towards reproducible builds. In the lwn.net article that discussed that push, one of Fedora’s spokespeople explicitly said that it would help combat supply chain attacks.

      So, all in all, I can confidently say that it did leave a mark on the Linux landscape. Hopefully, this specific attack vector will not be as viable in the foreseeable future.

Linux@programming.dev

linux@programming.dev

Subscribe from Remote Instance

Create a post
You are not logged in. However you can subscribe from another Fediverse account, for example Lemmy or Mastodon. To do this, paste the following into the search field of your instance: !linux@programming.dev

A community for everything relating to the GNU/Linux operating system

Also check out:

  • !linux_memes@programming.dev
  • !linuxphones@lemmy.ca

Original icon base courtesy of lewing@isc.tamu.edu and The GIMP

Visibility: Public
globe

This community can be federated to other instances and be posted/commented in by their users.

  • 565 users / day
  • 1.95K users / week
  • 3.6K users / month
  • 7.9K users / 6 months
  • 1 local subscriber
  • 7.96K subscribers
  • 996 Posts
  • 5.96K Comments
  • Modlog
  • mods:
  • Ategon@programming.dev
  • adr1an@programming.dev
  • dwraf_of_ignorance@programming.dev
  • BE: 0.19.11
  • Modlog
  • Instances
  • Docs
  • Code
  • join-lemmy.org