CaffeineFueled

86 Followers
56 Following
159 Posts
Just an admin doing admin stuff.
Bloghttps://ittavern.com/
Hosted Serviceshttps://ittavern.com/services/

Questions about the #xz situation:
1. do we know if only SSH is affected?
2. is it possible to remotely check if a system is affected?
3. what is the 'best' way to check if a system is affected as `xz --version` should be avoided?

#security

One more aspect that I think emphasizes the number of coincidences that had to come together to find this:

I run a number "buildfarm" instances for automatic testing of postgres. Among them with valgrind. For some other test instance I had used -fno-omit-frame-pointer for some reason I do not remember. A year or so ago I moved all the test instances to a common base configuration, instead of duplicate configurations. I chose to make all of them use -fno-omit-frame-pointer.

New job categories: Digital Archaeologist and Digital Historian. To the best of my knowledge, these careers don’t yet exist, but it’s high time they did. What we have so far…

Digital Archivist and Digital Curator
These jobs exist in a variety of fields, from managing medical X-ray records to managing digital photographs and data in a museum.

Computer Museums
There are currently various museums and private collections of computers, network equipment, and software. I doubt anyone is making a deliberate and methodical effort to catalog and document these collections on a global scale.

Internet Archive and the Wayback Machine
I just learned today that the Internet Archive, host of the Wayback Machine, (archive(dot)org) is IPv4 only. I don’t know what plans might be in the works to upgrade to IPv6, but today this represents an existential threat to one of the largest collections of historical web pages on the planet.

Old data formats are being lost. Several years ago, Scientific American published an article comparing deciphering old digital data to reading clay tablets. Even if the data is preserved – say, on a CD-ROM – it may be in a proprietary format that can only be read by a particular version of antiquated software that ran on a 32-bit processor. Does the documentation still exist to decode that data? What if the company went out of business and the founder walked away?

In a thousand years, understanding our global societies will depend as much, or more, on the preservation and interpretation of digital information as on the remnants of our cookware, clothing, and tools.

That’s why it’s time to begin today to create the jobs of Digital Archaeologist and Digital Historian. The rate of change is so rapid that our recent past is already slipping through our fingers.

"Cryptocurrencies are everything people don’t know about computers combined with everything they don’t understand about money."
if backdoors in open source projects were really that common GitHub copilot would’ve started suggesting them by now

Investing in OpenVPN/Wireguard shares right now.

Adding a limit order to sell them just in case we find a backdoor in them too.

"Don't run `xz --version' as previous versions may also be malicious".

I like this idea, but now we have to assume that all systems running an `xz` version from the last 2 years are potentially compromised.

#xz situation is a great reminder:

Don't expose any service to the Internet unless necessary - not even a hardened sshd.

We need a hashtag for US politics. Makes it easier to mute this bs.

xz --version
xz (XZ Utils) 5.2.5
liblzma 5.2.5

Is it enough to check if versions 5.6.0/1 are installed