GeistHaus
log in · sign up
23 pages link to this URL
Project statement about xz 5.6.1 (CVE-2024-3094)

Hi, tl;dr OpenWrt seems to be not affected by the CVE-2024-3094 As you may be aware, malicious code was identified in the xz upstream tarballs starting from version 5.6.0. The development snapshots of OpenWrt were utilizing this compromised library version. Fortunately, the snapshots builds relied on source code tarballs from GitHub releases, which are generated automatically. These contained only the dormant segment of the malicious code. The crucial component that would activate the backdoo...

2 inbound links website en
The Dependency Avalanche — Vivian Voss

644 strangers in your package.json. The XZ backdoor was caught by one engineer noticing half a second of latency. Next time it might be 50 milliseconds. Next time it might be no perceptible drift at all.

0 inbound links website en
Friday Links 24-10

Heisenberg’s indeterminacy principle formula. Two weeks of links, which includes a collection from the xz debacle. I loved reading these, as this is a good combination of spy story and technology postmortem. If you want to read an overview, read the timeline post. Good podcasts this week: about the Heisenberg principle, and the silencing of climate protesters in the UK. Leadership Getting real with Employee Experience [Podcast] - two good interviews with people active in the area.

0 inbound links article en post environmenturbanismfriday linksleadershipengineeringfridaylinks
xz/liblzma Compromise Link Roundup

Links to analysis, discussion and more related to the xz/liblzma compromise (CVE-2024-3094).

2 inbound links article en infosec xz/liblzma Compromise Link Roundupshellsharksinfosecsupplychain
gem.coop update #4: cooldowns beta

Hi again, everyone. We’ve got a big update for you, and we could use your help testing things out. If you just want to test the cooldowns beta, you can jump straight to the cooldown docs. The rest of this post has updates from the team, as well as more background on why we built cooldowns in the first place.

4 inbound links article en updates
xz backdoor - Dmitry Kudryavtsev

A malicious backdoor was discovered in xz library that implements LZMA compression. xz, among many other places, is used, indirectly, in sshd. My attempt to explain what happened.

1 inbound link article en Security CC BY-NC 4.0