Atemu@lemmy.ml to Linux@lemmy.ml · 8 months agobackdoor in upstream xz/liblzma leading to ssh server compromisewww.openwall.comexternal-linkmessage-square94fedilinkarrow-up1507arrow-down15cross-posted to: netsec@links.hackliberty.orgselfhosted@lemmy.worldlinux@lemmy.worldcybersecurity@sh.itjust.workssecurity@lemmy.ml
arrow-up1502arrow-down1external-linkbackdoor in upstream xz/liblzma leading to ssh server compromisewww.openwall.comAtemu@lemmy.ml to Linux@lemmy.ml · 8 months agomessage-square94fedilinkcross-posted to: netsec@links.hackliberty.orgselfhosted@lemmy.worldlinux@lemmy.worldcybersecurity@sh.itjust.workssecurity@lemmy.ml
minus-squarePossibly linux@lemmy.ziplinkfedilinkEnglisharrow-up10arrow-down1·8 months agoIt would be nice if we could press formal charges
minus-squaresim642@lemm.eelinkfedilinkarrow-up2·8 months agoAssuming that it’s just that person, that it’s their actual name and that they’re in the US…
minus-squareugjka@lemmy.worldlinkfedilinkEnglisharrow-up2arrow-down4·edit-28 months agothere will be federal investigation just speculation if the culprit is a foreign actor
minus-squarePossibly linux@lemmy.ziplinkfedilinkEnglisharrow-up14·8 months agoDo you have a source for this?
minus-squareWorseDoughnut 🍩@lemdro.idlinkfedilinkEnglisharrow-up6·8 months agoSource: they made it up
minus-squareVirulent@reddthat.comlinkfedilinkarrow-up2·8 months agoI don’t have a source but I think it is safe to say given the large corporations and government institutions that rely on XZ utils. I’m sure Microsoft, Amazon, redhat ect are in talks with the federal government about this
minus-squareugjka@lemmy.worldlinkfedilinkEnglisharrow-up2·8 months agoupdated my post, it was just some speculation i misread
It would be nice if we could press formal charges
Assuming that it’s just that person, that it’s their actual name and that they’re in the US…
there will be federal investigationjust speculation if the culprit is a foreign actorDo you have a source for this?
Source: they made it up
I don’t have a source but I think it is safe to say given the large corporations and government institutions that rely on XZ utils. I’m sure Microsoft, Amazon, redhat ect are in talks with the federal government about this
updated my post, it was just some speculation i misread