Conversation
Notices
-
Embed this notice
Haelwenn /элвэн/ :triskell: (lanodan@queer.hacktivis.me)'s status on Tuesday, 02-Apr-2024 09:18:03 JST Haelwenn /элвэн/ :triskell: @Gottox That's anything but a mitigation, in fact the only thing it would have done is make the discovery of it harder. -
Embed this notice
Enno T. Boland (gottox@chaos.social)'s status on Tuesday, 02-Apr-2024 09:18:05 JST Enno T. Boland A thing I wasn't aware of: systemd switched to dlopen'ing compression libraries on demand, rendering the #xz attack useless with one of their next releases. That's why apparently the attackers tried to push distributions to include the new xz version on their stable releases before the mitigation in systemd was included.
-
Embed this notice