@ABCmediawatch Re: last week's show.
I disagree with your characterisation of content for the "elites". Content is only for the elites if you're not explaining why a topic is important to everyone. Dumbing content down is just patronising. Have ABC staff watch The Newsroom.
Jia Tan's XZ attack was steps away from owning millions of devices. Buildroot uses & recommends XZ for images & upstream package code. Switching the XZ_SITE var to the "xz." subdomain in this config could've been enough but In this patch it is accepted only for documentation.
I've been looking into how the xz backdoor works and drew this sketch to make it easier to understand.
I'll update it as new information comes to light ✨
🤯 The level of sophistication of the XZ attack is very impressive! I tried to make sense of the analysis in a single page (which was quite complicated)!
I hope it helps to make sense of the information out there. Please treat the information "as is" while the analysis progresses! 🧐 #infosec #xz
@alanc @BruceDPorter Proper code reviews can be challenging and time consuming for the reviewers at the best of times... and that's when the author isn't trying to be deceptive and malicious.
Lots of analysis of the xz/liblzma vulnerability. Most skip over the first step of the attack:
0. The original maintainer burns out, and only the attacker offers to help (so the attacker inherits the trust of the project built by the maintainer).
Read their words👇🏻 1/
Interesting note on the #xz backdoor:
If you plot Jai Tan's commit history over time, the cluster of offending commits occurs at an unusual time compared to rest of their activity.
If the dev was pwned, it could be a sign that the threat actor contributed in their own timezone
The xz backdoor is, well, setting a fire under the entire Linux ecosystem... but I'm also so impressed with how it was set up: 2-yr maintainership, oss-fuzz, etc.
...and who knows how long it would've stayed undetected if the injected sshd code ran faster (<600ms)
Highlights:
If you needed yet another reason not to trust VPN providers or proxy services...
Here Facebook partnered with a bunch of companies to have root certificates installed on people's phones so they could intercept other app's traffic.
https://t.co/lwlU19JEYr
Last night, I was targeted for a sophisticated phishing attack on my Apple ID.
This was a high effort concentrated attempt at me.
Other founders are being targeted by the same group/attack, so I’m sharing what happened for visibility.
🧵 Here’s how it went down:
The PiDP-10 is done! The first 50 will be shipped next week. And soon, living rooms everywhere will be flooded with useful 1960s mainframes ;-)
To celebrate (it took 7 years), we also launched a new overview website for our computer replicas:
https://t.co/Rhg38E6vyQ
#pidp10
Announced today, we are collaborating as a launch partner with @Google in delivering Gemma, an optimized series of models that gives users the ability to develop with #LLMs using only a desktop #RTX GPU. https://t.co/WgWmC245se
today i found out that this one australian guy has been toiling away making incredibly detailed Neural Circuit Diagrams with the vibe of a 1950s issue of Popular Mechanics, but content fit for the 2020s
behold. the Transformer
The Bendix CADC is an analog computer used by fighter planes in the 1950s. It computed airspeed, Mach number, and other important parameters. I reverse-engineered how it performed these calculations with tiny gears, differentials, and cams. 1/12