Peter N. M. Hansteen on Nostr: This is one of the best explanations of the xz matter I have seen so far: and it ...
This is one of the best explanations of the xz matter I have seen so far:
https://lcamtuf.substack.com/p/technologist-vs-spy-the-xz-backdoorand it leads in with a quote to remember -
"This dependency existed not because of a deliberate design decisionby the developers of OpenSSH, but because of a kludge added by some Linux distributions to integrate the tool with the operating system’s newfangled orchestration service, systemd."
Enjoy!
#xz #opensource #security #openssh
Published at
2024-03-30 10:38:12Event JSON
{
"id": "a30778a0e7d27d7207d5e719b5d4fb5403acd206168c3e7459998d7d0daf0f72",
"pubkey": "528501bd0c0f9f712b482dbb2dfafa0e121590d6d89b097dc07780b2b8c38afa",
"created_at": 1711795092,
"kind": 1,
"tags": [
[
"t",
"xz"
],
[
"t",
"opensource"
],
[
"t",
"security"
],
[
"t",
"openssh"
],
[
"proxy",
"https://mastodon.social/users/pitrh/statuses/112184203183165167",
"activitypub"
]
],
"content": "This is one of the best explanations of the xz matter I have seen so far:\nhttps://lcamtuf.substack.com/p/technologist-vs-spy-the-xz-backdoor\n\nand it leads in with a quote to remember -\n\n\"This dependency existed not because of a deliberate design decisionby the developers of OpenSSH, but because of a kludge added by some Linux distributions to integrate the tool with the operating system’s newfangled orchestration service, systemd.\"\n\nEnjoy! \n\n#xz #opensource #security #openssh",
"sig": "fff9618deccfb2d443c4294d75f32e03aef73232684936006ab6b05e1a5decdc391e4b0d0ac217e540c021acade4d2cb539f777e7c0526d310c133bec8afb622"
}