Be aware of the upcoming 2nd anniversary on 27.03.:
"Andres Freund saved the World" 🎉
On that day, the persistent German discovered the back door in xz:
See the story behind it https://www.techflix.ch/videos/ac11000b-9d0a-1443-819d-0c0caa790000
Be aware of the upcoming 2nd anniversary on 27.03.:
"Andres Freund saved the World" 🎉
On that day, the persistent German discovered the back door in xz:
See the story behind it https://www.techflix.ch/videos/ac11000b-9d0a-1443-819d-0c0caa790000
The discovery of a backdoor in XZ Utils earlier this year shocked the open source community, raising critical questions about software supply chain security. This post explores whether better Debian packaging practices could have detected this threat, offering a guide to auditing packages and suggesting future improvements.\n
https://liblzma.so/ I made a thing. impulse control is for suckers
Lasse Collin (the developer of xz-utils) has found out how to accept donations without breaking the Finnish money collection law:
https://github.com/tukaani-project/xz/issues/105#issuecomment-2599004098
He has created an account on #LiberaPay with a restriction to not accept donations from Finns or people living in Finland:
https://liberapay.com/Larhzu/
I thought the case of the #xzbackdoor would be a really good way to make students aware of the many different dimensions of computing, and the “The Philosophy of the Open Source Pledge” https://vladh.net/the-philosophy-of-the-open-source-pledge/, which I assigned as reading, highlights many of the issues in a concise fashion.
Most students: 😴
Today, we launched the Open Source Pledge. Virtually all companies use Open Source software, making the Open Source ecosystem crucial to virtually all of the technology we use. That Open Source software is created and supported by maintainers. But the companies that use Open Source software almost never pay the maintainers anything. This means that the maintainers end up doing a huge amount of work for free, often as a second shift after their dayjob so that they can pay the bills, leaving them burned out and overworked, and leaving the projects they maintain at risk of serious security issues.
I wish this NPR podcast wasn't slanted against 'open source software' (not even mentioning FOSS). It is a very well composed and informative story about the XZ Attack, but it expressly states that open source methods were the vulnerability, implying this production method 'that built the internet' is now ending its beneficial phase. https://www.npr.org/2024/05/17/1197959102/open-source-xz-hack
Reminds me of the news splatter claiming the economic model is all bad. #XZBackdoor #FOSS