joonas-fi / joonas.fi

My personal blog
https://joonas.fi/
Apache License 2.0
3 stars 1 forks source link

Xz backdoor #118

Open joonas-fi opened 7 months ago

joonas-fi commented 7 months ago

https://news.ycombinator.com/item?id=39881556

https://news.ycombinator.com/item?id=39881454

https://maskray.me/blog/2021-01-18-gnu-indirect-function

https://research.swtch.com/xz-timeline

Auto conf / cmake

Rust, Go

Go uses code directly, no other way to influence build

Did the tar file contain other things than what the repo has?

C/C++ ld, ld configuration and glibc possibility to alter imports at runtime