XaiJu
thelinuxexperiment
thelinuxexperiment

patreon


Daily Linux & Open Source News - S01E68 - XZ Backdoor repercussions

Hey everyone!

In this one, we have:

https://linuxiac.com/ubuntu-24-04-lts-beta-release-postponed-due-to-security-concerns/

https://linuxiac.com/after-a-recent-ssh-vulnerability-systemd-reduces-dependencies/

https://9to5linux.com/linux-firmware-update-utility-fwupd-will-use-zstd-compression-for-future-releases

https://www.bleepingcomputer.com/news/security/new-xz-backdoor-scanner-detects-implant-in-any-linux-binary/

Have a nice day!

Daily Linux & Open Source News - S01E68 - XZ Backdoor repercussions

Comments

It seems to me that the longer term solution to the xz backdoor problem is to discourage the culture of anonymity in FOSS development. Jia Tan was a known and trusted contributor, yet still completely anonymous, and that is what I see as the core problem. I think FOSS projects are going to have to encourage face-to-face dev meetups and the exchange of personally identifiable information. The more robust a web of trust the FOSS community builds, the harder it will be for bad actors — even state sponsored ones — to inject rogue code into a project.

Zippy Wonderdust

Glad to see that solutions are being made. I use openSUSE and certainly didn't expect to have a backdoor installed on my system. Let's hope this kind of thing happens very rarely and gets caught quickly.

Michal Walach


More Creators