tech-pkg archive

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index][Old Index]

Re: Switching away from XZ



Am 04.04.24 um 04:24 schrieb Jonathan A. Kollasch:

There's been no indication that everyone at xz upstream is malicious,
just the few personas of the attacker.  I think we could all succumb to
social engineering attacks such as what let this happen.  It's very premature
to jump ship from xz at this point.

The attacker managed to get in 750 commits. Lasse (xz upstream) says it will take a long time to go through all of them and see what else could have been sabotaged. More signs of sabotage have already been found.

So, no, trying to avoid the attack surface by trying to use as little xz as possible for now is not premature at all.

--
Jonathan



Home | Main Index | Thread Index | Old Index