TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

The xz-utils backdoor has been removed

56 pointsby EveryPizzaabout 1 year ago

3 comments

rgovostesabout 1 year ago
This commit message is gold: <a href="https:&#x2F;&#x2F;github.com&#x2F;tukaani-project&#x2F;xz&#x2F;commit&#x2F;e93e13c8b3bec925c56e0c0b675d8000a0f7f754">https:&#x2F;&#x2F;github.com&#x2F;tukaani-project&#x2F;xz&#x2F;commit&#x2F;e93e13c8b3bec92...</a><p><pre><code> While the backdoor was inactive (and thus harmless) without inserting a small trigger code into the build system when the source package was created, it&#x27;s good to remove this anyway: - The executable payloads were embedded as binary blobs in the test files. This was a blatant violation of the Debian Free Software Guidelines. - On machines that see lots bots poking at the SSH port, the backdoor noticeably increased CPU load, resulting in degraded user experience and thus overwhelmingly negative user feedback. - The maintainer who added the backdoor has disappeared. - Backdoors are bad for security.</code></pre>
评论 #39986897 未加载
评论 #39987126 未加载
评论 #39988242 未加载
评论 #39988075 未加载
评论 #39988454 未加载
评论 #39987205 未加载
TillEabout 1 year ago
I&#x27;m relieved that the GitHub repo has finally been restored. I was just about to make a commit to fix our liblzma dependency, which would have required a vcpkg overlay to use a different upstream repo.
EveryPizzaabout 1 year ago
The security policy was also updated: <a href="https:&#x2F;&#x2F;github.com&#x2F;tukaani-project&#x2F;xz&#x2F;commit&#x2F;780d2c236de0e4749655696c2e0c26fb7565afd3">https:&#x2F;&#x2F;github.com&#x2F;tukaani-project&#x2F;xz&#x2F;commit&#x2F;780d2c236de0e47...</a>
评论 #39987426 未加载