i think the biggest news out of today's liblzma backdoor is that someone on earth is still capable of writing m4 code
Fascinating. Just yesterday the author added a SECURITY.md file to the xz-java project.
If you discover a security vulnerability in this project please report it privately. Do not disclose it as a public issue. This gives us time to work with you to fix the issue before public exposure, reducing the chance that the exploit will be used before a patch is released.
Reading that in a different light, it says give me time to adjust my exploits and capitalize on any targets. Makes me wonder what other vulns might exist in the author's other projects.
@vyr Yeah I was just talking elsewhere about how Jia isn't just the xz person...
Someone's gonna have to dig through everything they've done for the past year or so.
@trysdyn the other takeaway for today is that if you're a project maintainer, you can get a foreign intelligence agency to do a bunch of scutwork for you on their dime, provided you catch the exploit when it comes
@joepie91 @trysdyn security rule of thumb: anyone who offers to help your project is a commie spy. nobody would work with computers if they didn't have to