🤯 The level of sophistication of the XZ attack is very impressive! I tried to make sense of the analysis in a single page (which was quite complicated)!

I hope it helps to make sense of the information out there. Please treat the information "as is" while the analysis progresses! 🧐 #infosec #xz

@fr0gger god damn autoconf. it's so arcane that nobody thinks a bunch of extra seds and awks are weird

very nice diagram, thank you

@lritter @fr0gger

This, but also, it was hidden in a file that was .gitignore'd?