Debian 10 buster has moved to archive.debian.org freeing up space on our mirror network holding presently at 5,746GB across several architectures. More information on this move and other details: lists.debian.org/debian-devel-… #debian micronews.debian.org/2024/1711… #debian

I have been trying to tell CTOs for years that the time to give money to the projects in the middle of their stack that they’ve never heard of is *before* a crisis happens. But human nature being what it is, that’s a very hard sell.
mastodon.social/@glyph/1121809…


I really hope that this causes an industry-wide reckoning with the common practice of letting your entire goddamn product rest on the shoulders of one overworked person having a slow mental health crisis without financially or operationally supporting them whatsoever. I want everyone who has an open source dependency to read this message mail-archive.com/xz-devel@tuka…

Unfolding now: news.ycombinator.com/item?id=3…

- openwall.com/lists/oss-securit…
- github.com/tukaani-project/xz/…

An incredibly technically complex #backdoor in xz (potentially also in libarchive and elsewhere) was just discovered. This backdoor has been quietly implemented over years, with the assistance of a wide array of subtly interconnected accounts:

- github.com/tukaani-project/xz/…
- bugs.debian.org/cgi-bin/bugrep…
- github.com/jamespfennell/xz/pu…

The timeline on this is going to take so long to unravel

#security #linux

This entry was edited (1 year ago)
in reply to Evan B🥥ehs

I really hope that this causes an industry-wide reckoning with the common practice of letting your entire goddamn product rest on the shoulders of one overworked person having a slow mental health crisis without financially or operationally supporting them whatsoever. I want everyone who has an open source dependency to read this message mail-archive.com/xz-devel@tuka…

🚨 ⚠️ Emergency PSA: A critical security exploit was discovered in the xz package recently, used for compression and decompression on nearly all Linux distributions.

Rawhide users ARE impacted and should immediately STOP using Rawhide until the package update is fully rolled back. (1/3)

Security Advisory: redhat.com/en/blog/urgent-secu…

#Fedora #Linux #OpenSource #Security #Privacy

This entry was edited (1 year ago)

I accidentally found a security issue while benchmarking postgres changes.

If you run debian testing, unstable or some other more "bleeding edge" distribution, I strongly recommend upgrading ASAP.

openwall.com/lists/oss-securit…

reshared this

in reply to AndresFreundTec

I was doing some micro-benchmarking at the time, needed to quiesce the system to reduce noise. Saw sshd processes were using a surprising amount of CPU, despite immediately failing because of wrong usernames etc. Profiled sshd, showing lots of cpu time in liblzma, with perf unable to attribute it to a symbol. Got suspicious. Recalled that I had seen an odd valgrind complaint in automated testing of postgres, a few weeks earlier, after package updates.

Really required a lot of coincidences.

So when is native Exchange Support coming to Thunderbird - and what role does Rust play? Get the answer in this clip from our most recent office hours! 📼 🦀

Also, this video and ALL our videos going forward will have German subtitles. Ausgezeichnet! 🇩🇪

tilvids.com/w/u3MGYXHcNcS8G6HV…

#Thunderbird #Exchange #Rust

This entry was edited (1 year ago)

This is big: one of the xz-utils / liblzma *upstream maintainers* added malicious code to the last couple of releases. This is the person who actually publishes and signs the tarballs. If you are using liblzma 5.6.0 or 5.6.1 make sure to update your packages asap and consider reinstalling the OS or recreating the container.

openwall.com/lists/oss-securit…

in reply to Matt Campbell

I'm sure there are several lessons to learn from this, but here's the one that jumps out at me:

> openssh does not directly use liblzma. However debian and several other distributions patch openssh to support systemd notification, and libsystemd does depend on lzma.

This tells me that insisting on minimalism at every layer isn't premature optimization, and people who do so aren't wasting their time.

in reply to Matt Campbell

“simplicity” is a real load-bearing word there though :-). The simplicity we need to push for is in the social trust graph, the superficial simplicity of less code doesn’t really help with this problem unless the “less code” is maintained by fewer people we have to trust.

But requiring that there be fewer people per LOC in the loop creates other problems of sustainability and brittleness

in reply to Brian Campbell

@unlambda @glyph Sure, I use both open-source and proprietary software every day. Practically, I can't say one is clearly better than the other. But one of the obvious answers to all the concerns about open-source sustainability is that we should pay more for our software, to make sure the maintainers are fairly compensated. But the availability of so much stuff free of charge sets up a strong incentive to take without paying. If nobody put out anything for free, that problem wouldn't exist.
in reply to Matt Campbell

So what direct actions can we individual developers, sysadmins, and business owners (I'm co-owner of a tiny SaaS company) take, while the xz/liblzma exploit is fresh on our minds, to prevent something like this from happening again? I really want to know if there's something I should do today. If not, who *can* do something about it? I don't feel comfortable dismissing this as the sole province of those with a lot more money; that seems like too easy a way to avoid doing anything.

Venku je příjemně fajn, mít tak ten domeček na kolečkách, odjela bych pryč z města, na kraj lesa, kde je výhled do krajiny, poslouchala zpěv ptáků, bzučení včel a kochala se... 🥲 Místo toho koukám v paneláku do zdi, nad hlavou mi dupou a hádají se sousedi, otrávená realitou, svázaná systémem, nic mě nebaví a sen o svobodě se čím dál víc vzdaluje...

Now that we have fully offline ISOs #bluefin can ship with @thunderbird right on the dock, as intended. Looks great, and I love the ptyxis icon so much lol.

universal-blue.discourse.group…

This entry was edited (1 year ago)
in reply to Steve Troughton-Smith

One thing AltStore does that should really get you thinking about alternative payment systems that Apple never would have considered: it has Patreon integration, and can tie access to apps to your Patreon pledge — which gives you an entirely different, personal relationship with your users, and lets you use the same reward system you use for videos, blog posts, merch etc. Alternative app stores don’t just have to recreate Apple’s model. And this provides a CTF-friendly avenue (and 1M user cap)
This entry was edited (1 year ago)

This right here is why I have no sympathy for "but accessibility is too hard!"

Someone went out of their way to write code to make their login less accessible. What if they'd put that same energy into making it more accessible?

mastodon.social/@Edent/1121780…

Met trots kijken we terug op de vooruitgang die we het afgelopen jaar hebben geboekt. Hier zijn enkele mijlpalen van 2023:

🔐 Veiliger inloggen steeds meer de norm
💻 480.078.039 inlogs met hashtag#DigiD
✉️ 85.683.611 berichten verstuurd via hashtag#MijnOverheid
👑 A-status DigiD
✅ Makkelijker doorlopende machtigingen inzien

Bekijk ons jaarverslag voor het hele overzicht van de belangrijke ontwikkelingen. 👉 logius.nl/onze-organisatie/log…