(03-29-2024, 06:56 PM)Dartz Wrote: Someone slipped a bit of a mickey into XFZ library to allow remote access
Oh dear.
Fortunately this was caught soon enough to only affect Fedora Rawhide, Kali and a Debian release. Or - basically - nothing that's actually (or should be) in production.
Yeah it was one month from making it into an Ubuntu LTS from that Debian release. We all got very lucky, since this was a long-term attack. Either the guy was planted by a government, or co-opted by a government. The attack needed a secret key to work, too.
Cue the hand-wringing about how open-source development doesn't give individuals enough support; just like the thoughts and prayers we offer school shootings, it should have the same effect.
"Kitto daijoubu da yo." - Sakura Kinomoto