🤯 The level of sophistication of the XZ attack is very impressive! I tried to make sense of the analysis in a single page (which was quite complicated)!

I hope it helps to make sense of the information out there. Please treat the information “as is” while the analysis progresses! 🧐 #infosec #xz

I’ve found the best #meme about #xz #backdoor.

So, kids, what’s the moral of the XZ story?

If you’re going to backdoor something, make sure that your changes don’t impact its performance. Nobody cares about security - but if your backdoor makes the thing half a second slower, some nerd is going to dig it up.

people are saying the xz backdoor is likely the work of a nation state actor, and given that it appears to been slow rolled for a couple of years and immediately became obsolete before it was fully launched - you do have to admit it bears the hallmarks of a government IT project

Raise your hand if you ever made a paper snake out of tear-off tractor-feed margins.

xz-utils was backdoored by its upstream. Tracked as CVE-2024-3094 and thoroughly documented by vuln discoverer Andres Freund on oss-security@: openwall.com/lists/oss-securit

@simon import textwrap
Batteries included, remember? :-)

This deepfake cryptography cipher suite tier debate between Trump, Obama, and Biden is totally NSFW and totally genius. Laughed. so. freaking. hard. securitycryptographywhatever.c

#Google announced that starting in June 2024, ad blockers such as uBlock Origin #uBO will be disabled in Chrome 127 and later with the rollout of Manifest V3 (#Mv3).

#ManifestV3 is deceitful and threatening to your privacy, and now is a good time to switch to #Firefox (@Mozilla@mamot.fr) (@mozilla@mozilla.social ) and/or #TorBrowser if you haven’t done so already!

| ̄ ̄ ̄ ̄ ̄ ̄ ̄ ̄ ̄ ̄|
| Install  |
| firefox  |
(\__/) ||
(•ㅅ•) ||
/   づ

The value of OSS today?

“from $1.22 billion to $6.22 billion if we were to decide as a society to recreate all widely used OSS on the supply side”

“from $2.59 trillion to $13.18 trillion, if each firm who used an OSS package had to recreate it from scratch”

“5% of programmers are responsible for more than 90% of the value created on the supply- and demand- side”

The report: papers.ssrn.com/sol3/papers.cf

@karlauerbach Rewrite using async/await?

@chm OK, danke!

@chm Gibt es eine Möglichkeit, zu steuern, welche Posts in meinem RSS-Feed erscheinen? Ich sehe nur Original-Toots, nicht aber Replies und Boosts.

16:15 [/bb-atom]

@johnmacintosh That’s exactly what I wrote my first BASIC programs on!

Für Kurzentschlossene: Morgen ist Velobörse in Lyss:

00:46 [/bb-atom]


@thomasweibel Ist in Europa nicht am 22/7? 😆

✨ new tech bingo ✨

