Wasn't #Bellingcat doing an entire investigation thing around Jia Tan and the xz stuff.
What happened there?
Wasn't #Bellingcat doing an entire investigation thing around Jia Tan and the xz stuff.
What happened there?
Visit https://fern.deals/brilliant for 20% off of a premium subscription. Start learning new skills today! It's also a great way to support our channel. (ad)...
I fixed a typo in the README; no one cared.
I executed an intricate plan of making significant contributions to the repository over the course of 5 years, became a maintainer, and then added a backdoor; everyone freaked out.
No one notices until you start making big moves.
Was wissen wir eigentlich über «Jia Tan»? Ich habe mich mal auf eine Spurensuche begeben. Und dabei herausgefunden, dass man mit der Sicherheitslücke wohl mehrere Milliarden hätte verdienen können.
Ich nehme euch gerne mit auf diese Reise und die Schlussfolgerungen, die sich daraus ergeben.
#JiaTan #xz #Backdoor #xzBackdoor #DNIP
https://dnip.ch/2024/05/14/spurensuche-jia-tan-xz/
@pastermil @linux the attack surface for something that isn't officially maintained by the developers, and that doesn't have more vetting (e.g. distribution packages) opens up room for malicious actors.
e.g. #arch / #aur recommends verifying scripts manually before installing, and malicious scripts have been found and removed.
There are actors like #jiatan out there. An unofficial #flatpak needs manual verification before install - that's why I just go with #snap if the flatpak isn't official
New #Ubuntu 24.04 with compromised #xz? #JiaTan will be happy. #ITSecurity
Neues #Ubuntu 24.04 mit kompromittiertem #xz? #JiaTan wird sich freuen. #ITSecurity #ITSicherheit
Jia Tan changes all Open Source contributions forever.
On my projects: Oh, coming over with a PR for an "innocent" feature are we? Quite the Jia Tan move.
On other projects i am contributing to: just extending this to fix on old obscure version, adding a test... hope no one thinks i'm doing groundwork for a Jia Tan.