GNU social JP
  • FAQ
  • Login
GNU social JPは日本のGNU socialサーバーです。
Usage/ToS/admin/test/Pleroma FE
  • Public

    • Public
    • Network
    • Groups
    • Featured
    • Popular
    • People

Conversation

Notices

  1. Embed this notice
    Matt Blaze (mattblaze@federate.social)'s status on Monday, 01-Apr-2024 06:54:19 JST Matt Blaze Matt Blaze

    An interesting thing about the XZ sabotage is that, while it was very cleverly obfuscated (congratulations to Andres Freund for finding it!), once found, it is very clear that it's a deliberate backdoor. It can't be explained away as an ordinary bug that introduced a vulnerability.

    Says something about the tradeoff space the attacker was working in.

    In conversation about a year ago from federate.social permalink
    • gidi likes this.
    • Embed this notice
      Matt Blaze (mattblaze@federate.social)'s status on Monday, 01-Apr-2024 06:58:33 JST Matt Blaze Matt Blaze
      in reply to
      • Noah Cook

      @UncivilServant is disagree that that’s inconsistent with a state actor. Personalized, long game infiltration is how spies and HUMINT has always worked.

      In conversation about a year ago permalink
      gidi likes this.
    • Embed this notice
      Noah Cook (uncivilservant@med-mastodon.com)'s status on Monday, 01-Apr-2024 06:58:34 JST Noah Cook Noah Cook
      in reply to

      @mattblaze You're one of the first I've seen to analyze this in terms of the adversary's constraints. I am not a computer scientist, but in terms of constraints, resources, and targeting, this doesn't "feel" like a state actor.

      So, this is highly targeted, and the social engineering tactics seemed personal. You're not getting that from a committee. And it was a long game, which would have meant supervisors coming and going, changes in priority, etc in government.

      In conversation about a year ago permalink

      Attachments


Feeds

  • Activity Streams
  • RSS 2.0
  • Atom
  • Help
  • About
  • FAQ
  • TOS
  • Privacy
  • Source
  • Version
  • Contact

GNU social JP is a social network, courtesy of GNU social JP管理人. It runs on GNU social, version 2.0.2-dev, available under the GNU Affero General Public License.

Creative Commons Attribution 3.0 All GNU social JP content and data are available under the Creative Commons Attribution 3.0 license.