lemmy.mlaga97.space
  • Communities
  • Create Post
  • Create Community
  • heart
    Support Lemmy
  • search
    Search
  • Login
  • Sign Up
Fubarberry@sopuli.xyz to Arch Linux@lemmy.mlEnglish · 1 year ago

The xz package has been backdoored, you need to update your system now

archlinux.org

external-link
message-square
41
fedilink
0
external-link

The xz package has been backdoored, you need to update your system now

archlinux.org

Fubarberry@sopuli.xyz to Arch Linux@lemmy.mlEnglish · 1 year ago
message-square
41
fedilink
Arch Linux - News: The xz package has been backdoored
archlinux.org
external-link
  • SubArcticTundra@lemmy.ml
    link
    fedilink
    arrow-up
    0
    ·
    1 year ago

    Why does xz exist anyway?

    • Supermariofan67@programming.dev
      link
      fedilink
      arrow-up
      0
      ·
      1 year ago

      It provides liblzma, an implementation of the lzma compression algorithm

      • Youser11@lemmy.world
        link
        fedilink
        arrow-up
        0
        ·
        1 year ago

        That’s why I use dz instead. It provides ligma. It’s a much better compression algorithm.

      • jack@monero.town
        link
        fedilink
        arrow-up
        0
        ·
        edit-2
        1 year ago

        Why does lzma exist anyway?

        • tetris11@lemmy.ml
          link
          fedilink
          arrow-up
          0
          ·
          edit-2
          1 year ago

          Exactly. People should just use zip for their compression libraries. Way more efficient

          • jack@monero.town
            link
            fedilink
            arrow-up
            0
            ·
            1 year ago

            What are you talking about?

            • tetris11@lemmy.ml
              link
              fedilink
              arrow-up
              0
              ·
              edit-2
              1 year ago

              Zip and WinRAR (the paid version obviously) being a good way to do compression over ssh, clearly

        • Supermariofan67@programming.dev
          link
          fedilink
          arrow-up
          0
          ·
          1 year ago

          I don’t understand what you mean by this question… Because someone decided to create it?

        • 5714@lemmy.dbzer0.com
          link
          fedilink
          English
          arrow-up
          0
          ·
          1 year ago

          https://www.youtube.com/watch?v=VPj_dILDK6I

          • SubArcticTundra@lemmy.ml
            link
            fedilink
            arrow-up
            0
            ·
            edit-2
            1 year ago

            This looks interesting, I’m gonna watch it

    • jack@monero.town
      link
      fedilink
      arrow-up
      0
      ·
      1 year ago

      One purpose I know of is to snoop on users

      • ezchili@iusearchlinux.fyi
        link
        fedilink
        arrow-up
        0
        ·
        1 year ago

        Stop posting

    • shirro@aussie.zone
      link
      fedilink
      English
      arrow-up
      0
      ·
      edit-2
      1 year ago

      It is a compression library that is in the dependency tree for a large number of other packages though not as many as zlib which is in practically everything.

      xz development appears to have been compromised by some organisation in a long game targeting sshd in Debian and derivatives. Debian maintainers have a nasty habit of adding lots of patches to upstream sources which occasionally have unintended consequences. I am a long term Debian user but I wish they would stop doing this. Thankfully arch generally doesn’t modify upstream as much as Debian and arch sshd doesn’t link in the backdoored library.

      • SubArcticTundra@lemmy.ml
        link
        fedilink
        arrow-up
        0
        ·
        1 year ago

        Ah I see. Are there any reasons why people would choose to use xz over zlib?

        • Supermariofan67@programming.dev
          link
          fedilink
          arrow-up
          0
          ·
          1 year ago

          It compresses much better, by a lot, as zlib/deflate is an ancient algorithm made back when computers only had a few megabytes of ram.

          Nowadays though, zstd seems to be replacing both of them, as at max level it compresses about as well as xz while also being faster. Nevertheless, many programs link against all the common compression algorithms (xz/zlib/zstd/bz2) to support everything

          • SubArcticTundra@lemmy.ml
            link
            fedilink
            arrow-up
            0
            ·
            1 year ago

            Ah I see

Arch Linux@lemmy.ml

archlinux@lemmy.ml

Subscribe from Remote Instance

Create a post
You are not logged in. However you can subscribe from another Fediverse account, for example Lemmy or Mastodon. To do this, paste the following into the search field of your instance: !archlinux@lemmy.ml

The beloved lightweight distro

Visibility: Public
globe

This community can be federated to other instances and be posted/commented in by their users.

  • 2 users / day
  • 4 users / week
  • 27 users / month
  • 187 users / 6 months
  • 0 local subscribers
  • 8.84K subscribers
  • 274 Posts
  • 1.26K Comments
  • Modlog
  • mods:
  • k_o_t@lemmy.ml
  • BE: 0.19.5
  • Modlog
  • Instances
  • Docs
  • Code
  • join-lemmy.org