556: The xz Backdoor Exposed 🚨 episode artwork

EPISODE · Apr 1, 2024 · 1H 10M

556: The xz Backdoor Exposed 🚨

from LINUX Unplugged · host Jupiter Broadcasting

We're breaking down the attack: how it works, how it was hidden, and why time was running out for the attacker.Sponsored By:Tailscale: Tailscale is a programmable networking software that is private and secure by default - get it free on up to 100 devices!Kolide: Kolide is a device trust solution for companies with Okta, and they ensure that if a device isn't trusted and secure, it can't log into your cloud apps.Support LINUX UnpluggedLinks:💥 Gets Sats Quick and Easy with Strike📻 LINUX Unplugged on Fountain.FMoss-security mailing list — Backdoor in upstream xz/liblzma leading to ssh server compromise.Fedora AnnouncementDebian AnnouncementUbuntu AnnouncementKali Linux AnnouncementArch Linux AnnouncementGentoo AnnouncementopenSUSE Tumbleweeed AnnouncementNixOS Unstable DiscussionWhy does it take two weeks for NixOS to replace xz?Andres Freund on Mastodon — I was doing some micro-benchmarking at the time, needed to quiesce the system to reduce noise. Saw sshd processes were using a surprising amount of CPU, despite immediately failing because of wrong usernames etc....rwmj on Hacker News — Very annoying - the apparent author of the backdoor was in communication with me over several weeks trying to get xz 5.6.x added to Fedora 40 & 41 because of its "great new features"A Microcosm of the interactions in Open Source projects — Make no mistake. This is the way it works. It needs to change.Devuan GNU/Linux on X — Devuan is not affected by the latest vulnerability caused by systemd.systemd PR: Dynamically load compression librariesMatteo Croce on X — I'm the author of such PR. While I absolutely didn't know that libxz had a backdoor, I really think that libraries should be loaded on-demand when rarely used, hence my change :)Ryan C. Gordon on X — This is probably how the xz thing happened, right?Jan Wildeboer on the Fediverse — Again the FOSS world has proven to be vigilant and proactive in finding bugs and backdoors, IMHO.Unplugged Core MembershipTXLF is coming up! — April 12 - 13 in Austin, Texas.LFNW coming up! — April 26 - 28Mobile Game Ads Are Boosting Podcast Follower Counts — Wondery, iHeart and Lemonada Media are all using a non-public product from MowPod - which gives extra lives and game credits to gamers if they follow shows on Apple Podcasts from game apps.MowPod's podcast promotion tools: tales from the barfortydeux's NixOS ConfigsPrism Launcher — An Open Source Minecraft launcher with the ability to manage multiple instances, accounts and mods.World Backup Day — March 31st — One small accident or failure could destroy all the important stuff you care about.Updating Our Fiddly Bits | LINUX Unplugged 494

NOW PLAYING

556: The xz Backdoor Exposed 🚨

0:00 1:10:03

No transcript for this episode yet

We transcribe on demand. Request one and we'll notify you when it's ready — usually under 10 minutes.

Linux For Everyone Jason Evangelho An upbeat, conversational show about the exciting world of desktop Linux, open source software, and the community creating it. The Power and The Punchline Unplugged Studios *THE POWER AND THE PUNCHLINE*Hosted by *Mick Hunt* and *Rudy Rush*Two worlds. One mission. Power and perspective meet comedy and culture.Mick Hunt, the modern voice of self-improvement and purpose, joins forces with Rudy Rush, nationally recognized comedian, TV host, and one of the sharpest talents in the industry. Together, they deliver a show that proves growth does not have to be serious, and laughter does not mean you are not learning.Each episode dives into honest conversations about life, culture, purpose, relationships, success, and the BECAUSE that keeps us moving. The power comes from the truth. The punchline makes it unforgettable.If you want conversations that make you think, laugh, and grow at the same time, this is your space.*Because sometimes the best lessons come with a laugh.* Destination Linux Deviant Airwaves Destination Linux is a weekly show where Ryan, Jill, & guests share their passion for Linux & Open Source. Destination Linux is a show for all experience levels, whether you’re a beginner to Open Source or a Guru of Sudo, this is the podcast for you. Destination Linux covers a wide range of topics from the latest news, discussions on Linux & Open Source, gaming on Linux, unique in-depth interviews and much more! Linux For The Rest Of Us - Podnutz Podnutz.com A podcast for anyone even remotely interested in Linux. We cover linux news, distros, open source software, and much more. Dip your toe in and learn how linux can help you! Hosted by Steve Cherubino and Steve McLaughlin. Another great tech podcast from Podnutz.com

Frequently Asked Questions

How long is this episode of LINUX Unplugged?

This episode is 1 hour and 10 minutes long.

When was this LINUX Unplugged episode published?

This episode was published on April 1, 2024.

What is this episode about?

We're breaking down the attack: how it works, how it was hidden, and why time was running out for the attacker.Sponsored By:Tailscale: Tailscale is a programmable networking software that is private and secure by default - get it free on up to 100...

Can I download this LINUX Unplugged episode?

Yes, you can download this episode by clicking the download button on the episode player, or subscribe to the podcast in your preferred podcast app for automatic downloads.
URL copied to clipboard!