Fascinating. Just yesterday the author added a SECURITY.md file to the xz-java project.

If you discover a security vulnerability in this project please report it privately. Do not disclose it as a public issue. This gives us time to work with you to fix the issue before public exposure, reducing the chance that the exploit will be used before a patch is released.

Reading that in a different light, it says give me time to adjust my exploits and capitalize on any targets. Makes me wonder what other vulns might exist in the author's other projects.

@vyr Yeah I was just talking elsewhere about how Jia isn't just the xz person...

Someone's gonna have to dig through everything they've done for the past year or so.

@trysdyn the other takeaway for today is that if you're a project maintainer, you can get a foreign intelligence agency to do a bunch of scutwork for you on their dime, provided you catch the exploit when it comes

@vyr Oh there's going to be Intelligence Agency involvement far beyond what we've got going on.

This hasn't even begun to be an incident yet; we're still in the panic-fire-putting-outting stage. When an orchestrated sitdown on what the hell to do happens it's gonna be nasty.

Follow

@trysdyn @vyr I'm actually quite concerned about the second-order effects that this incident is going to have in the current discourse climate...

· · Web · 1 · 0 · 2

@joepie91 @trysdyn security rule of thumb: anyone who offers to help your project is a commie spy. nobody would work with computers if they didn't have to

Sign in to participate in the conversation
Pixietown

Small server part of the pixie.town infrastructure. Registration is closed.