"Isn't that a bit alarmist?" No!
xz is a base-system package in literally every distro I know of. It's everywhere.
Compromised releases have been out for five weeks and we didn't notice. We only noticed because someone caught openssh taking 10x as long to do DH exchanges and auth. If the attacker had been sneakier we wouldn't have noticed at all.
The compromised xz was in Fedora's testing versions and they didn't notice. You had the compromised version in Arch for a month (and arguably still do, but a combination of build method and source acquisition method likely renders it safe).
If some random guy didn't go "Why is openssh so slow?" and dig really deep into that, it would have hit stable/live distros and then what? We don't know.
@trysdyn Yeah, someone is almost certainly going to prison over this at the end. liblzma and xz are going to be extensively audited if it turns out the maintainer is responsible, and may never be considered safe considering how sophisticated the obfuscation on the injection sequence is
@yassie_j would be a pity if someone put together WALL is STOP...
@Jo I've always wondered what an FPGA implementation of the Pico-8 would look like when put on an ASIC
@Decimal Alright, I'm glad you have that option
@charlene @deejvalen Dwagon! Dwagon! Dwagon!
@Decimal still a damn shame. I hope the S22 still works over wifi at least
@lyncia I didn't realize they all had those names and that makes them even cuter dhglsdhgd
@deejvalen in a couple months tho
@greene my dumb ass over here crying over cute bugs whose lives can be measured in weeks
It's the Trans Week of Visibility, and today I'm hostin' cozy chat games for a cause!
Come chat, chill, have some fun, and support TransLifeline: stream's up in 1hr!
I'm Elfi! I'm a fair folk, magical moth, greyace girl, greenhorn gamedev, in my thirties and , and ADHD+ASD+EDS. Disclosure: white
💕 Aine @SophicLeech
💕 Agi @AgiDine
💕 Jenny @Esme
💕 Cherry @deejvalen
Icon by @Zwiebelprinz, header from Liar Princess and the Blind Prince by NIS