[ om / jp / 2d ] [ home ]

/jp/ - 2D/Random

Name
Email
Subject
Comment
File
Password (For file deletion.)

File: 1712268940169.png (534.78 KB, 760x576, 8f8c5742234c79627723ff0364….png)

No. 617777

whatmin what do you think of the xz utils exploit that was capable of giving full root ssh access to literally any machine running the latest version of the package and was discovered only by accident? why is linux so shit?

No.617778

this happened like a week ago you retard

No.617779

File: 1712270087357.jpg (19.25 KB, 512x288, 8328887255dc2c3a027c709a8b….jpg)


No.617780

File: 1712270373249.jpg (340.11 KB, 828x871, 1712177296516078.jpg)

I've been afraid of upstream supply-chain malware and also malicious distro package maintainers for years now.

I've been called paranoid, "concern trolling", etc. so I always just shut up about it, but it feels good to be a little bit vindicated, and hopefully community awareness and prevention around this issue improves.

I only update Arch once every two months, I upgrade and reboot with no internet access, and check Wireshark to see if there is anything trying to make network connections, or any suspicious processes running.

I've also been thinking about downloading updates a week before I plan to upgrade (pacman -Syuw), and then installing them offline (pacman -Su), so anything I install would have had everyone else beta-test for a week, and if I don't hear nerds shouting from every rooftop that ransomware was inserted into [small library package that no one gives a fuck about it] I assume I'm fine.

No.617781

File: 1712271108027.png (1005.33 KB, 1280x720, a480f0b814ea005ef34ee7d166….png)

>>617780
yeah but how can you trust anything going forward? this didn't show up in the source code, and was discovered purely by chance because a windows dev was doing some benchmarking and noticed performance discrepancies

how can you know for certain you aren't running a malicious package with an unknown backdoor and the CIA is covertly monitoring you making all these anti USA pro china posts on ota?

i would just stop using computers at this point if i were you

No.617782

File: 1712271296964.jpg (28.79 KB, 272x332, 1711917714895805.jpg)

>>617781
Network monitoring mainly. I trust that I would see the malware making network connections on Wireshark, or my OpenWRT router's network monitor.

No.617783

this is a weird maki quads thread

No.617784

>>617782
what if the malicious package modified wireshark so it wouldn't show when connections were made through the backdoor, also how can you know for certain your OpenWRT firmware isn't compromised as well?

besides, i really doubt you're monitoring your network at all times

No.617786

>>617785
what if my friend henri came back and posted on ota again

No.617787

File: 1712272996715.jpg (117.85 KB, 1280x720, [SubsPlease] Snack Basue -….jpg)




Delete Post [ ]
[Return]
[ om / jp / 2d ] [ home ]