Skip Navigation

InitialsDiceBearhttps://github.com/dicebear/dicebearhttps://creativecommons.org/publicdomain/zero/1.0/„Initials” (https://github.com/dicebear/dicebear) by „DiceBear”, licensed under „CC0 1.0” (https://creativecommons.org/publicdomain/zero/1.0/)AN
Posts
0
Comments
354
Joined
2 yr. ago

  • This is the original email by the person who discovered this backdoor. But if you want you can search for xz backdoor and you'll find a lot more articles which explain timelines and other things. https://www.openwall.com/lists/oss-security/2024/03/29/4

     
        
     == Observing Impact on openssh server ==
    
    With the backdoored liblzma installed, logins via ssh become a lot slower.
    
    time ssh nonexistant@...alhost
    
    before:
    nonexistant@...alhost: Permission denied (publickey).
    
    before:
    real	0m0.299s
    user	0m0.202s
    sys	0m0.006s
    
    after:
    nonexistant@...alhost: Permission denied (publickey).
    
    real	0m0.807s
    user	0m0.202s
    sys	0m0.006s
    
      

    That's a 500ms or 0.5s difference

  • They don't need to guess the password. If you don't have full disk encryption I can just run another os in live mode and mount your drive and read everything. And even change the password to your fedora, by changing the hash in shadow file

  • OK let me add fuel to the fire. here in Andy's response he says the tweet was from last year which is technically true but it was from December 2024.

    Also how can he think that Trump stands for little guys when he has elon musk as his pet monkey

  • What would US gain by doing this, they already have most of Europe in their sphere of influence, if they break up Europe, France, Germany, and maybe UK (if they fix their shit) will be major players with their own spheres, US won't have any, and I doubt US will be able to occupy and control Greenland even if they can win it quickly, Greenland is a big land mass and US troops have very little experience fighting in such a cold environment.