We’re thrilled to announce we’re partnering with @OpenAI to bring best in class technical knowledge and the world’s most popular LLM models for AI development together! This groundbreaking partnership with OpenAI will drive our mission to empower the world to develop technology through collective knowledge.
https://t.co/CbgZIEoB2z
@m_aty@Bashmohandes It took him 2 years though. He has been actively working and allegedly pushing useful features, engaging with distro maintainers, etc
Until he decided to push the backdoor.
What I find to be interesting in the whole xz saga is that the *bad* maintainer worked in the project for almost 2 years and established credit before pushing the change with the backdoor.
The whole story is also interesting of how he became a maintainer, since the original maintainer mentioned that he didn't have time, I also read somewhere that he was burnt out.
Lots of analysis of the xz/liblzma vulnerability. Most skip over the first step of the attack:
0. The original maintainer burns out, and only the attacker offers to help (so the attacker inherits the trust of the project built by the maintainer).
Read their words👇🏻 1/
there is no escape from software complexity, you just get to choose the place where it happens
anyone that tells you otherwise is trying to sell you something
Imo this could be chaotic in the long run
Just use the Options pattern and inject the values through env vars.
You may use appsettings as a fallback for local dev stuff.