Email or username:

Password:

Forgot your password?
Top-level
scy

There is now a GitHub issue in the xz repository inquiring about whether this has been intentional or not.

github.com/tukaani-project/xz/

3 comments
scy

I'm not saying that it looks like someone has specifically targeted xz and played the long game by helping out a maintainer that was overworked and suffered from mental health issues

but it does look like someone has specifically targeted xz and played the long game by helping out a maintainer that was overworked and suffered from mental health issues

mastodon.social/@glyph/1121809

scy

Meanwhile, #Debian is considering rolling #xz back not only to the point before the backdoor was added, but to where the person who _wrote_ the backdoor hadn't contributed any code to xz yet.

Which means considering creating patches to fix ABI breakage such a rollback would cause.

bugs.debian.org/cgi-bin/bugrep

For all the trash talk Debian gets for being "pedantic" and slow to change: They put in the _work_ to do things _right_. I respect that.

via hachyderm.io/@joeyh/1121815129

(Edit: English is hard.)

Meanwhile, #Debian is considering rolling #xz back not only to the point before the backdoor was added, but to where the person who _wrote_ the backdoor hadn't contributed any code to xz yet.

Which means considering creating patches to fix ABI breakage such a rollback would cause.

bugs.debian.org/cgi-bin/bugrep

Go Up