Why Nostr? What is Njump?
2024-03-30 10:13:44
in reply to

Kevin Beaumont on Nostr: Another two thoughts on XZ - - sshd itself has no dependency on the XZ utils library. ...

Another two thoughts on XZ -

- sshd itself has no dependency on the XZ utils library. The streams got crossed in a way I don’t think anybody understood (except the threat actor).

- had that backdoor been performant with sshd, I don’t think anybody would have spotted it.

The way this played out opens a window of opportunity to go back and look at both issues.
Author Public Key
npub176rs4lx7gjqwepgg75psfpv7zjj3xz0lyj4n7rux93ftm390sars6fkwlw