Domain changed to archive.palanq.win . Feb 14-25 still awaits import.
[3 / 1 / 1]

How does the xz backdoor will affect linux/open source?

No.1453244 View ViewReplyOriginalReport
After all the xz racket, really how compromised its the kernel/open source model?
it isn't deactivated by simply using another version or xz utils/lib or disabling the ssh service?
How much of the linux ecosystem is compromised since anyone can make edits?
Have we seen the full extent of the backdoor (on linux/android/windows) or there will be more?*
What it the latest version of xz safe for sure?
Why does the vector limited to /x86_64/glibc and debs/rpm distros? Why not go full mode with
arm or other versions like slackware?

*it seems to have done commits to windowze
https://github.com/libarchive/libarchive/commits?author=JiaT75