tukaani-project / xz

XZ Utils
https://tukaani.org/xz/
Other
503 stars 40 forks source link

[Feature Request]: please rewrite this library in rust #102

Closed jmwielandt closed 3 months ago

jmwielandt commented 3 months ago

Describe the Feature

About the backdoor report (https://www.cve.org/CVERecord?id=CVE-2024-3094), an "easy" fix to ensure is impossible to happen again is to rewrite xz in rust.

Expected Complications

Will I try to implement this new feature?

No

AffSeda commented 3 months ago

You... want the malicious threat actor to re-write his malicious threat in Rust, so that it's a memory-safe malicious backdoor?

Theldus commented 3 months ago

As if rewriting in <safest-language-that-exists> would prevent malicious people from committing to the project...

jmwielandt commented 3 months ago

@AffSeda @Theldus oh fuck, you are right! XDDD please tukaani-project, do NOT rewrite xz in rust.

Doclic commented 3 months ago

Describe the Feature

About the backdoor report (https://www.cve.org/CVERecord?id=CVE-2024-3094), an "easy" fix to ensure is impossible to happen again is to rewrite xz in rust.

Expected Complications

* Learning rust

* Regain comunity trust

* Integration with other softwares that depends on xz.

Will I try to implement this new feature?

No

this project should clearly be rewritten in haskell so that it's too confusing to write a backdoor for!!

Co3co commented 3 months ago

Never open an issue on GitHub ever again, for everybody's sake.

reitowo commented 3 months ago

you should more like, rewrite yourself in rust