• 0 Posts
  • 26 Comments
Joined 6 months ago
cake
Cake day: January 2nd, 2024

help-circle



  • TL;DR don’t worry (for now) - it only impacts rpm and deb builds and impacted releases only really made it into OpenSuSe tumbleweed - if you’re running bleeding edge maybe you need to worry a little.

    A laymans explanation about what happens is that the malicious package uses an indirect linkage (via systemd) to openssh and overrides a crypto function which either:

    • allows access to the system to a particular key
    • allows remote code execution with a particular key

    Or both!

    I have secondhand info that privately the reverse engineering is more advanced, but nobody wants to lead with bad info.

    As for what you should do? Unless you’re running an rpm or deb based distro and you have version 5.6.0 or 5.6.1 of xz-utils installed, not much. If you are, well, that comes down to your threat model and paranoia level: either upgrade (downgrade) the package to a non-vulnerable version or dust off and nuke the site from orbit; it’s the only way to be sure.









  • I’m not an expert

    Clearly.

    Ukraine were to have access to F-18s, F-35s, or any NATO asset, it would implicate NATO

    Bullshit. Everything you just listed is in use by non-NATO countries. The primary drivers for “unlocking” new varieties of aid to Ukraine appear to be:

    • battlefield utility in the near future (javelin, himars/m270, western IFVs, tanks etc).
    • sending a message to that western support is locked in for the long term (repair facilities, announcements around reconstruction aid)

    the geo-political consequences of Ukraine having NATO weapons is enormous… … [It would] … further escalate the conflict towards a NATO-Russian war (World War 3), and the precipitation of nuclear assets.

    Russia has claimed that every single new weapons system delivered is “escalatory” and threatens nuclear war every single time. Please stop spreading their propaganda for them.

    This is why even France’s own Dassault assets and Sweden’s Saabs were not offered.

    Are you sure that it has to do with this and not the fact that there were more F-16s produced than each of the alternatives combined?







  • Taiwan (Republic of China) and China (People’s Republic of China) are different governments that both lay claim to the same territory.

    The TL;DR is that in 1949 the communists won the Chinese civil war and the remaining nationalist opposition retreated to Taiwan, beginning the state of affairs that we have today.

    PRC considers Taiwan part of its core territory and will not renounce its claims. RoC has, since 1991, officially recognised that they can’t retake the mainland, but there’s ongoing debate about whether or not Taiwanese reunification or an independent Taiwan is the end state.