Skip to main content


Jia Tan's history of commits on #xz suggests that every png file in gcc or apache or whatever is a possible attack vector now.

https://joeyh.name/blog/entry/reflections_on_distrusting_xz/

#xz
in reply to see shy jo

Why assume that Lasse Collin will do anything at all in response to the attack? Yes, he put up the xz-backdoor page now, but I don't think we should expect him to do more. We already know he was burnt out in 2022; that's why Jia Tan was able to step in to begin with. I'm not sure what the exact solution is, but the project needs a new, trustworthy, funded maintainer or maintainers.
in reply to Matt Campbell

Or at least, if we expect Lasse Collin to pick the project back up now, then someone should hire him to do that, with generous pay, assuming he's free to quit his current job. Unfortunately, I'm not in a position to do that.