glynmoody,
@glynmoody@mastodon.social avatar

The Mystery of ‘Jia Tan,’ the XZ #Backdoor Mastermind - https://www.wired.com/story/jia-tan-xz-backdoor/ "The thwarted XZ Utils supply chain attack was years in the making. Now, clues suggest nation-state hackers were behind the persona that inserted the malicious code." another reason for governments to support #opensource properly

rdnielsen,
@rdnielsen@floss.social avatar

@glynmoody
Suggesting that a nation-state was behind this hack implicitly discounts the possibility that there are unscrupulously self-interested private-sector actors.

"Possibility" may not be the right word.

glynmoody,
@glynmoody@mastodon.social avatar

@rdnielsen I think nation state seems more likely given the huge amount of planning and patience required - not features of greedy companies...

rdnielsen,
@rdnielsen@floss.social avatar

@glynmoody
I agree with "more likely" but, although nation-states and private big tech companies may have a common interest in breaching users' security, there is at least one big tech company that has historically seen Linux as an existential threat, and acted to compromise it persistently over decades. So although the number of potential bad actors in the private sector may be smaller than the number of nation-states, the former number is not zero.

glynmoody,
@glynmoody@mastodon.social avatar

@rdnielsen not sure they care about undermining open source these days, because they have learned how to coopt it, as usual....

ArneBab,
@ArneBab@rollenspiel.social avatar

@glynmoody timezone inferences like these are why Sharesite in Freenet / Hyphanet chooses a random hour of the day when the Sharesite is created and only uploads during that hour.

@Freenet

glynmoody,
@glynmoody@mastodon.social avatar

@ArneBab sensible @Freenet

QuadRadical,
@QuadRadical@wetdry.world avatar

@glynmoody I managed to read the original article using reader mode:

glynmoody,
@glynmoody@mastodon.social avatar

@QuadRadical glad you managed in the end

QuadRadical,
@QuadRadical@wetdry.world avatar

@glynmoody well I guess I'm not reading that

glynmoody,
@glynmoody@mastodon.social avatar
QuadRadical,
@QuadRadical@wetdry.world avatar

@glynmoody hmm, that page won't load.

glynmoody,
@glynmoody@mastodon.social avatar

@QuadRadical works fine here...not sure why it times out

  • All
  • Subscribed
  • Moderated
  • Favorites
  • opensource
  • ngwrru68w68
  • rosin
  • GTA5RPClips
  • osvaldo12
  • love
  • Youngstown
  • slotface
  • khanakhh
  • everett
  • kavyap
  • mdbf
  • DreamBathrooms
  • thenastyranch
  • magazineikmin
  • megavids
  • InstantRegret
  • normalnudes
  • tacticalgear
  • cubers
  • ethstaker
  • modclub
  • cisconetworking
  • Durango
  • anitta
  • Leos
  • tester
  • provamag3
  • JUstTest
  • All magazines