Announcement

Collapse
No announcement yet.

GitHub Disables The XZ Repository Following Today's Malicious Disclosure

Collapse
X
 
  • Filter
  • Time
  • Show
Clear All
new posts

  • Originally posted by StarterX4 View Post
    It is. Time to switch to Zstd and ditch legacy libraries and standards.
    according to the german wikipedia :

    "The settings are such that decompression is about 1300 percent faster than xz, while the packet size increases by about 0.8 percent.[13]​"

    the compression ratio is not as good as xz...

    yes its faster but many times performance does not matter and compression ratio is all what matters.
    Phantom circuit Sequence Reducer Dyslexia

    Comment


    • Originally posted by qarium View Post

      according to the german wikipedia :

      "The settings are such that decompression is about 1300 percent faster than xz, while the packet size increases by about 0.8 percent.[13]​"

      the compression ratio is not as good as xz...

      yes its faster but many times performance does not matter and compression ratio is all what matters.
      It is not possible to characterise a compressor or a decompressor with a single number for speed or compression ratio, not least because the program is often tunable, trading off speed, compression ratio, and possibly memory usage; results will also depend on the data being compressed, with some data being easier for some programs to compress than others. This means a simple statement about speed and compression ratios is likely to be wrong.

      There are many online resources showing the results of testing different compression/decompression programs against test data. It is a good idea to review several such tests to give some basis for deciding whether a particular compressor/decompressor is suitable for your use-case, or not. This is not a case where there are simple answers where a single program covers all cases optimally. Life's complicated.

      Comment


      • https://twitter.com/fr0gger_/status/...tfw%7Ctwcamp%5 Etweetembed%7Ctwterm%5E1774342248437813525%7Ctwgr% 5E9131e31ca9a29707f741643fba4b4d7384070ef4%7Ctwcon %5Es1_&ref_url=https%3A%2F%2Fwww.derstandard.de%2F story%2F3000000213960%2Fwie-die-computerwelt-gerade-haarscharf-an-einer-sicherheitskatastrophe-vorbeigeschrammt-ist

        Picture: XZ Outbreak (CVE-2024-3094)


        Phantom circuit Sequence Reducer Dyslexia

        Comment


        • Originally posted by AmericanLocomotive View Post
          This is why I think Linux packaging is a failure right now. The constant "Just fork it!" nature of Linux is spreading resources too thin. Too many different package managers. Too many different software repositories with overworked packagers trying to keep up with the thousands of applications a distro might have. Too many different distributions that are all largely the same except for some very superficial differences.
          So as a result, no one is actually taking the time to double check and review things. XZ is a critical core component of many distributions and software packages. If a critical component, and an otherwise stable feature-complete application gets an update, it should be scrutinized to the fullest extent.
          Instead of we have spread-thin package maintainers that just vacuum it up without a second thought.
          I get that it's difficult to understand what someone else's code is doing, but that's why the KML requires certain standards and comments that clearly explain what the code is trying to do.
          For critical components like XZ, maintainers should just flat out reject updates without clear comments that carefully explain what each new addition is doing.
          "the thousands of applications a distro might have."

          i see the complete opposite the last years distro's have less and less application packaged

          the reason for this is they drop 32bit i386 packages and .lib's and .dll's and go with 64bit only. even WINE/Proton drops 32bit usersprace libs and go with WOW64

          there are other reasons why distro's have less and less packages and less application in their distro repo because more and more apps are imigrated to flatpak and flathub.org

          "Too many different software repositories"

          also this is wrong to... there are only 2 with any significant marketshare and it is valve steam for games and flathub.org

          all other software repositories have nearly zero marketshare.

          I have fedora 40 beta installed and use valve steam and flathub.org and everything else most people don't need it.
          Phantom circuit Sequence Reducer Dyslexia

          Comment


          • All Linux distros should abandon XZ alltogether in my opinion. There is no reason to use it, it is a garbage format to begin with, now with malware inside too? No way... There are many alternatives.

            Comment


            • Originally posted by mSparks View Post
              Yeah, but they give us high comedy like
              Current and former customers of the US telecoms firm are impacted by the breach, the company says.

              I still remember the height of the "nothing to hide nothing to fear" days, TBH, nothing actually changed there, they are just quieter than they used to be.
              I don't think OSS is special tbh, Its just like those countries that actually put their corrupt politicians in jail - they aren't more corrupt, it's just more visible.
              Rasberybery Pis used to have default Pi/Pi user/pass logins, now every ssh server that goes online will log a thousand plus failed Pi logins a day.
              right OSS is not special but still there are people who claim phoronix.com forum members are not under systematic attack.

              to my own experience i can say for sure yes phoronix.com forum members are under attack. systematic attack.
              Phantom circuit Sequence Reducer Dyslexia

              Comment


              • Originally posted by Old Grouch View Post
                It is not possible to characterise a compressor or a decompressor with a single number for speed or compression ratio, not least because the program is often tunable, trading off speed, compression ratio, and possibly memory usage; results will also depend on the data being compressed, with some data being easier for some programs to compress than others. This means a simple statement about speed and compression ratios is likely to be wrong.
                There are many online resources showing the results of testing different compression/decompression programs against test data. It is a good idea to review several such tests to give some basis for deciding whether a particular compressor/decompressor is suitable for your use-case, or not. This is not a case where there are simple answers where a single program covers all cases optimally. Life's complicated.
                right but give me your opinion is xz legacy and zstd​ the future ? do you advice to abolish xz in favor of Zstandard/Zstd ?
                Phantom circuit Sequence Reducer Dyslexia

                Comment


                • Originally posted by TemplarGR View Post
                  All Linux distros should abandon XZ alltogether in my opinion. There is no reason to use it, it is a garbage format to begin with, now with malware inside too? No way... There are many alternatives.
                  if you use gnome 46 and you go into the explorer/file manager and make right click on a file and click on compression you can only choose
                  between:

                  .zip
                  .tar.xz
                  .7z

                  well someone should tell these gnome developers to add Zstandard/Zstd

                  the reason is really .zip is totally outdated and obsolete and .tar.xz is only used in linux and mac

                  and well .7z you need to install 7zip in windows... and no one knows why microsoft add this open standard to windows ..

                  Phantom circuit Sequence Reducer Dyslexia

                  Comment


                  • Originally posted by qarium View Post

                    if you use gnome 46 and you go into the explorer/file manager and make right click on a file and click on compression you can only choose
                    between:

                    .zip
                    .tar.xz
                    .7z

                    well someone should tell these gnome developers to add Zstandard/Zstd

                    the reason is really .zip is totally outdated and obsolete and .tar.xz is only used in linux and mac

                    and well .7z you need to install 7zip in windows... and no one knows why microsoft add this open standard to windows ..
                    This is not just about GNOME. Personally i want it out of the packaging systems, the kernel, etc. Anyone who is foolish enough to keep wanting to use XZ should be free to keep using it, i just don't want it shoved on my OS no more... Reverting to a "safe" version won't cut it for me in the long run, it is clear that the maintainer of the XZ doesn't care about it and doesn't guarantee its safety, therefore, there is absolutely no reason for any serious distribution to keep using it in the future. Who knows what else is there? Who knows if more issues may arise in the future? I don't care about 0,1% better compression than other formats when there is absolutely no reliability whatsoever...

                    Comment


                    • Originally posted by You- View Post
                      I saw a link to a mailing list post from 2022 where the maintainer informed people that he was suffering from mental health issues (causing updates to be slower than usual).

                      The responses were most unkind, "You ignore the many patches bit rotting away on this mailing list. Right now you choke your repo.​".

                      I think it was the new maintainer who did this.

                      I wonder how much those original responses lead to this incident.

                      EDIT: Link to the mailing list posts: https://www.mail-archive.com/xz-deve.../msg00567.html
                      Perhaps he was, perhaps he wasn't "suffering" and instead some foreign agency bribed him to begin "suffering" and allow them to inject trojan horses in there and have plausible deniability... That is for law enforcement to figure out. But XZ's reliability is totally compromized at this point, i hope Archlinux which is my distro of choice dumps XZ as fast as possible. It essentially has no maintainers and can't be trusted.

                      Comment

                      Working...
                      X