Daniel's weekly report March 29, 2024
lists.haxx.se/pipermail/daniel…
distros, releases, curl up, webinar, c-ares, 10k days, xz
Daniel's weekly report March 29, 2024
lists.haxx.se/pipermail/daniel…
distros, releases, curl up, webinar, c-ares, 10k days, xz
Debian 10 buster has moved to archive.debian.org freeing up space on our mirror network holding presently at 5,746GB across several architectures. More information on this move and other details: https://lists.debian.micronews.debian.org
I have been trying to tell CTOs for years that the time to give money to the projects in the middle of their stack that they’ve never heard of is *before* a crisis happens. But human nature being what it is, that’s a very hard sell.
mastodon.social/@glyph/1121809…
Unfolding now: news.ycombinator.com/item?id=3…
- openwall.com/lists/oss-securit…
- github.com/tukaani-project/xz/…
An incredibly technically complex #backdoor in xz (potentially also in libarchive and elsewhere) was just discovered. This backdoor has been quietly implemented over years, with the assistance of a wide array of subtly interconnected accounts:
- github.com/tukaani-project/xz/…
- bugs.debian.org/cgi-bin/bugrep…
- github.com/jamespfennell/xz/pu…
The timeline on this is going to take so long to unravel
Updates the vendored version of xz to be 5.6.1. Also updates the vendor script to support the addition of SPDX-License-Identifier headers into some files.GitHub
🚨 ⚠️ Emergency PSA: A critical security exploit was discovered in the xz package recently, used for compression and decompression on nearly all Linux distributions.
Rawhide users ARE impacted and should immediately STOP using Rawhide until the package update is fully rolled back. (1/3)
Security Advisory: redhat.com/en/blog/urgent-secu…
#Fedora #Linux #OpenSource #Security #Privacy
Red Hat Information Risk and Security and Red Hat Product Security learned that the latest versions of the “xz” tools and libraries contain malicious code that appears to be intended to allow unauthorized access., (Red Hat)
Three more org members in the Foundation, a new beta for Fractal, and matrix-docker-ansible-deploy moving away from Redis. That, and much more happened This Week in Matrix
matrix.org/blog/2024/03/29/thi…
Matrix, the open protocol for secure decentralised communicationsThib (matrix.org)
m.youtube.com/watch?v=jDzi9l6V…
Provided to YouTube by OpusMám ťa rád · Karol Duchoň20 naj, Vol. 2℗ 2016 OPUS a.s.Composer: Benjamin David FindonComposer: Leslie Sebestian CharlesLyricist: ...YouTube
I accidentally found a security issue while benchmarking postgres changes.
If you run debian testing, unstable or some other more "bleeding edge" distribution, I strongly recommend upgrading ASAP.
reshared this
I was doing some micro-benchmarking at the time, needed to quiesce the system to reduce noise. Saw sshd processes were using a surprising amount of CPU, despite immediately failing because of wrong usernames etc. Profiled sshd, showing lots of cpu time in liblzma, with perf unable to attribute it to a symbol. Got suspicious. Recalled that I had seen an odd valgrind complaint in automated testing of postgres, a few weeks earlier, after package updates.
Really required a lot of coincidences.
So when is native Exchange Support coming to Thunderbird - and what role does Rust play? Get the answer in this clip from our most recent office hours! 📼 🦀
Also, this video and ALL our videos going forward will have German subtitles. Ausgezeichnet! 🇩🇪
tilvids.com/w/u3MGYXHcNcS8G6HV…
Is support for Microsoft's Exchange protocol coming to the desktop version of Thunderbird? What about K-9 Mail and Thunderbird for Android? What's the timeline? Here's your answer in a short video clip from our recent Community Office Hours session.TILvids
@gumnaam Hey there! Everything is fine! Last year the financial report came out in the beginning of May, so the 2023 report should be out around the same time. Hope this helps calm any worries!
~Monica
This is big: one of the xz-utils / liblzma *upstream maintainers* added malicious code to the last couple of releases. This is the person who actually publishes and signs the tarballs. If you are using liblzma 5.6.0 or 5.6.1 make sure to update your packages asap and consider reinstalling the OS or recreating the container.
I'm sure there are several lessons to learn from this, but here's the one that jumps out at me:
> openssh does not directly use liblzma. However debian and several other distributions patch openssh to support systemd notification, and libsystemd does depend on lzma.
This tells me that insisting on minimalism at every layer isn't premature optimization, and people who do so aren't wasting their time.
“simplicity” is a real load-bearing word there though
. The simplicity we need to push for is in the social trust graph, the superficial simplicity of less code doesn’t really help with this problem unless the “less code” is maintained by fewer people we have to trust.
But requiring that there be fewer people per LOC in the loop creates other problems of sustainability and brittleness
Can we at least seccomp / landlock / bwrap or similar our CLI tools?
There's no reason a (de-)compression CLI like xz has unrestricted filesystem access and could even do network calls in 2024.
It’s finally happening — sideloading is coming to the EU!
We’ve started the process of becoming a legitimate “app marketplace”, allowing our European friends to download @delta and other AltStore apps officially for the first time ever!
See you in March ☘️
Delta Chat looks and feels like other popular messenger apps, but does not involve centralized tracking and control.Accessible Android
This is my first time ever in a stadium. It’s where my mother in law is married today
Now that we have fully offline ISOs #bluefin can ship with @thunderbird right on the dock, as intended. Looks great, and I love the ptyxis icon so much lol.
universal-blue.discourse.group…
Hey ya’ll, thanks to @dogphilosopher 's heroic last minute efforts fighting with R2 we’ve got new Bluefin ISOs up! We now ship the Flatpaks on the ISO itself, allowing for a full offline installation.Universal Blue
This right here is why I have no sympathy for "but accessibility is too hard!"
Someone went out of their way to write code to make their login less accessible. What if they'd put that same energy into making it more accessible?
mastodon.social/@Edent/1121780…
Found a whole new level of security incompetence. Went to type in my 2FA code, but nothing appeared on screen. They hadn't disabled pasting. Instead, they used JavaScript to ensure that only numbers could be typed in.Mastodon
10,000 bugfixes in 10,000 days
Yeah, I think you're right - how we choose to categorize issues can result in different conclusions, and it's not all that useful anyways.
We need both features and bug fixes, and any change can introduce security issues, even if they look innocuous and even if they're fixing another security issue.
Wow. Tell me how you really feel!
Samsung can't blame #Apple's #iPhone monopoly for a lifetime of terrible software
techradar.com/phones/samsung-g…
Slap the TouchWiz from the GalaxyPhilip Berne (TechRadar)
Met trots kijken we terug op de vooruitgang die we het afgelopen jaar hebben geboekt. Hier zijn enkele mijlpalen van 2023:
🔐 Veiliger inloggen steeds meer de norm
💻 480.078.039 inlogs met hashtag#DigiD
✉️ 85.683.611 berichten verstuurd via hashtag#MijnOverheid
👑 A-status DigiD
✅ Makkelijker doorlopende machtigingen inzien
Bekijk ons jaarverslag voor het hele overzicht van de belangrijke ontwikkelingen. 👉 logius.nl/onze-organisatie/log…
het lijkt erop dat de hastags stuk zijn hier, wellicht een fout van een crossposter?
Maar belangrijker: waar blijft de broncode van digid en de digidapp? #publicmoneypubliccode Ik kan nog steeds de digid app niet installeren!
Zem 🇪🇹 🇪🇺
in reply to Debian • • •