tech-pkg archive

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index][Old Index]

Re: Switching away from XZ



Am 04.04.24 um 02:04 schrieb Jörg Sonnenberger:

One thing we need to discuss for sure is the blame game currently
being played by quite a few parties. "You merged a Jia Tan commit,
you must be a plant as well!" Personally, I find the danger of that kind of
attitude turning away a lot of volunteers a lot more harmful.

I'm not seeing the article author or any of us here playing the blame game, though?

I never said we should discuss who to blame, but what else the attacker has probably lined up, given the level of sophistication we saw, and what we could do to reduce the attack surface.

Disabling sandboxes is a pretty good sign the attacker has something else they want to use. Combine that with the attacker having added an entirely new decoder, and I'd say there's a high risk.

--
Jonathan



Home | Main Index | Thread Index | Old Index