this post was submitted on 01 Apr 2024
445 points (97.6% liked)

linuxmemes

20464 readers
563 users here now

I use Arch btw


Sister communities:

Community rules

  1. Follow the site-wide rules and code of conduct
  2. Be civil
  3. Post Linux-related content
  4. No recent reposts

Please report posts and comments that break these rules!

founded 1 year ago
MODERATORS
 

\s obviously

all 14 comments
sorted by: hot top controversial new old
[โ€“] [email protected] 30 points 4 months ago (1 children)

JIA CHEONG TAN

TEACHING JOAN

[โ€“] [email protected] 49 points 4 months ago* (last edited 4 months ago)

HENTAI CAN JOG ๐Ÿ†๐Ÿฅซ๐Ÿƒ
NINJA HATE COG ๐Ÿฅท๐Ÿ˜กโš™๏ธ
A JOINT CHANGE ๐Ÿšฌ๐Ÿ”„
HANG IT CEO JAN ๐Ÿ•ด๏ธ
GAIN JET NACHO โœˆ๏ธ๐Ÿฅ™โž•
GOAT-CHIN JANE ๐Ÿง”โ€โ™€๏ธ
GONNA CITE HAJ ๐ŸŽ™๏ธ๐Ÿฆˆโž
ANCIENT HAG JO ๐Ÿง™๐Ÿปโ€โ™€๏ธ
ENJOING A CHAT ๐Ÿ˜„๐Ÿ’ฌ

[โ€“] [email protected] 27 points 4 months ago

Wait a minute:

CIA AGENT JOHN

I TAG JOHN CENA

The real answer is right in front of us all along. He played us all for fools.

[โ€“] [email protected] 19 points 4 months ago (3 children)
[โ€“] [email protected] 21 points 4 months ago* (last edited 4 months ago)

Former maintainer of the .xz project for about a year or two. Hid a backdoor into the code that almost made it into many bigger distros if it wasn't found by a Microsoft employee.

[โ€“] [email protected] 16 points 4 months ago (2 children)

More specifically, it's the name used by the attacker. Could well be multiple people, or if it's one person (still almost certainly state-funded, but the state can fund one person), a fake name nevertheless. We have no info about this person's real life identity. They used a VPN in Singapore, and some people have looked at the times of the commits to try guess a timezone, though that's not foolproof as they could've just been a nocturnal person, or even tried to schedule commits to happen at a time to suggest they're in a different timezone, though I think the latter is unlikely and overkill.

[โ€“] [email protected] 6 points 4 months ago

Yep seems like a bigger organisation being involved considering fact that this was brewing 2+ years.

[โ€“] [email protected] 6 points 4 months ago

so it's very well possible that they're a CIA agent named John?

[โ€“] [email protected] 10 points 4 months ago

i think it's the person that snuck in the xz vulnerability