Oddbean new post about | logout
 THE XZ UTILS BACKDOOR IS A STARK REMINDER THAT IF YOU RELY ON BITCOIN IT IS IMPERATIVE TO SUPPORT THE OPEN SOURCE CONTRIBUTORS THAT MAKE THIS MOVEMENT POSSIBLE.

GOOD MORNING.

https://www.wired.com/story/jia-tan-xz-backdoor/ 
 Slow burn. I was tasked with checking all of our systems to ensure the exploited version wasn’t in our farm. 
 As far as I know It’s a very specific attack. You need to run a distribution that is rolling release _and_ uses the binary tarball of XZ while having the SSH system notify thing on. Its almost specifically sorts out Debian testing derivatives and Fedora.

For example, Arch has the infected binary but its SSH is not linked to it. NixOS will have the 5.6.1 version but its clean because they’ve built from source instead of using the published binaries.

But if you have something important running on those servers that got touched by those exploits its better to just wipe clean and redeploy those machines. 
 Correct. Kali was another one. Fedora rawhide, a few opensuse as well. No Debian or RHEL release 
 GM. Bullish on xz compression, systemd, openssh and other fee software. 
 GOOD MORNING ☀️ 
 GM ☕ @ODELL 🫂 THIS IS HOW WE WIN 🤙 
 🫡 GOOD MORNING 
 Good morning. #supportTheOpenSourceAutists 
 Paywalled. 😐 
 does  @OpenSats issue any grants for security researchers ? we can't just rely on open source autism alone.. even if it works 99.999% of the time lol 
 GM 🤠🤙 OPEN SOURCE EVERYTHING  
 Good morning ☕️ 
 GM! 
 GM CHIEF 🫡 
 GM 
 GM☕ 
 GM 🫡 
 GM great reminder 
 GOOD MORNING. 💀 🌹 https://m.primal.net/HrsV.mov  
 good morning 🌞🌞 
 GM!!! 
 GM

apathy re:bitcoin development is an attack on bitcoin 
 Gm bro ☕ 🫂 
Good vibes 🤙 
#Opensource ✊  
 GM, wouldn't want to be a compliance officer for any major software company amirite 
 Good morning. Lots of love and respect for open source devs. This should be a no brainer. @saylor what is your opinion on this? 
 GOOD MORNING. THIS IS A FRIENDLY REMINDER THAT @saylor AND #MSTR RELY ON BITCOIN. 🫂💜🤙 
 Jis Tan isn't the individual's real name.

This individual is possibly an intelligence operative for Mossad, the CIA or MI6. 
 SMELLS LIKE CCP TO ME BUT YEA LIKELY A STATE OP. 
 GOOD MORNING (`・ω・´)ゞ⚡おはよう 
 Support open source contributors 
 GOOD FUCKING SNOWSTORM MORNING 
 Don't let yourself get backdoored...support open source devs ---> opensats.org

nostr:note16xf4uc9y2y7ywkwwyefdp438dz7vcmp6cqsd8jzz6ud7prah80fqxz65gx  
 Damn right keep the pressure on Sayler. His pockets are deeper than mine. 
 And whatever he says people do and believe 🤷🏽‍♂️ 
 the Amish have been warning us for years. why didn't we listen?! 👨‍🌾 
 SUPPORT THE AUTISTS 
 Bad actors are everywhere, supported, unsupported or commercialized (Ex Sam Bankman-Fried). The best way is to have a moral-ethical code of conduct and monetize your work, people will pay for valuable tech, especially if at its core-business is making money. 
 You know when a chat room is one to avoid when you post the above from @odell and everyone ignores you. #foss