Steinar H. Gunderson

Sat, 30 Mar 2024 - xz backdooring

Andres Freund found that xz-utils is backdoored, but could not (despite the otherwise excellent analysis) get quite to the bottom of what the payload actually does.

What you would hope for to be posted by others: Further analysis of the payload.

What actually gets posted by others: “systemd is bad.”

Update: Good preliminary analysis.

[11:39] | | xz backdooring

Wed, 27 Mar 2024 - git grudge

Small teaser:

Probably won't show up in aggregators (try this link instead).

[18:56] | | git grudge

Steinar H. Gunderson <steinar+blog@gunderson.no>