1 point
*

At least microsoft is honest enough to admit their software needs protection, unlike apple and unlike most of the people who have made distros of linux. (edit: microsoft is still dishonest about what kind of protection it needs though)

Even though apple lost a class action lawsuit for false advertising over the claim “mac can’t get viruses” they still heavily imply that it doesn’t need an antivirus.

any OS can get infected, it’s just a matter of writing the code and finding a way to deliver it to the system…Now you might be thinking “I’m very careful about what I click on” that’s a good practice to have, but most malware gets delivered through means that don’t require the user to click on anything.

You need an antivirus on every computer you have, linux, android, mac, windows, iOS, all of them. There’s loads of videos on youtube showing off how well or not so well different antivirus programs work for windows and android.

permalink
report
reply
19 points

A “antivirus” tends to be a proprietary black box. Such “antivirus” programs could not of detected the XZ backdoor

permalink
report
parent
reply
-4 points

But a good whitelisting antivirus could’ve stopped it.

permalink
report
parent
reply
2 points

All it took was one set of nerd eyeballs

permalink
report
parent
reply
18 points

Any additional information been found on the user?

permalink
report
reply
2 points

Probably Chinese?

permalink
report
parent
reply
26 points
*

Can’t confirm but unlikely.

Via https://boehs.org/node/everything-i-know-about-the-xz-backdoor

They found this particularly interesting as Cheong is new information. I’ve now learned from another source that Cheong isn’t Mandarin, it’s Cantonese. This source theorizes that Cheong is a variant of the 張 surname, as “eong” matches Jyutping (a Cantonese romanisation standard) and “Cheung” is pretty common in Hong Kong as an official surname romanisation. A third source has alerted me that “Jia” is Mandarin (as Cantonese rarely uses J and especially not Ji). The Tan last name is possible in Mandarin, but is most common for the Hokkien Chinese dialect pronunciation of the character 陳 (Cantonese: Chan, Mandarin: Chen). It’s most likely our actor simply mashed plausible sounding Chinese names together.

permalink
report
parent
reply
3 points

That actually suggests not Chinese due to naming inconsistencies

permalink
report
parent
reply
3 points

So this doesn’t really tell us one way or the other who this person is or isn’t.

permalink
report
parent
reply
2 points

Just because somebody picked a vaguely Chinese-sounding handle doesn’t mean much about who or where.

permalink
report
parent
reply
2 points

That’s why I put the question mark

permalink
report
parent
reply
4 points
*

They’re more likely to be based in Eastern Europe based on the times of their commits (during working hours in Eastern European Time) and the fact that while most commits used a UTC+8 time zone, some of them used UTC+2 and UTC+3: https://rheaeve.substack.com/p/xz-backdoor-times-damned-times-and

permalink
report
parent
reply
3 points

It is also hard to be certain as they could be a night owl or a early riser.

permalink
report
parent
reply
12 points
*

as long as you’re up to date on everything here: https://boehs.org/node/everything-i-know-about-the-xz-backdoor

the only additional thing i’ve seen noted is a possibilty that they were using Arch based on investigation of the tarball that they provided to distro maintainers

permalink
report
parent
reply
66 points

In a nutshell you say…

permalink
report
reply
8 points
*

I’m going to read it later, but if I don’t find a little red Saddam Hussein hidden in there I’ll be disappointed

edit: eh my day wasn’t good anyway

permalink
report
parent
reply
33 points

Coconut at least…

permalink
report
parent
reply
69 points

permalink
report
reply
119 points

Thank you open source for the transparency.

permalink
report
reply
69 points

And thank you Microsoft.

permalink
report
parent
reply
65 points

Shocking, but true.

permalink
report
parent
reply
14 points

They just pay some dude that is doing good work

permalink
report
parent
reply

Linux

!linux@lemmy.ml

Create post

From Wikipedia, the free encyclopedia

Linux is a family of open source Unix-like operating systems based on the Linux kernel, an operating system kernel first released on September 17, 1991 by Linus Torvalds. Linux is typically packaged in a Linux distribution (or distro for short).

Distributions include the Linux kernel and supporting system software and libraries, many of which are provided by the GNU Project. Many Linux distributions use the word “Linux” in their name, but the Free Software Foundation uses the name GNU/Linux to emphasize the importance of GNU software, causing some controversy.

Rules

  • Posts must be relevant to operating systems running the Linux kernel. GNU/Linux or otherwise.
  • No misinformation
  • No NSFW content
  • No hate speech, bigotry, etc

Related Communities

Community icon by Alpár-Etele Méder, licensed under CC BY 3.0

Community stats

  • 8.1K

    Monthly active users

  • 6.4K

    Posts

  • 174K

    Comments