Hacker Newsnew | past | comments | ask | show | jobs | submitlogin
Openbsd's xz port maintainer looks at the build stages of the malicious code (marc.info)
41 points by binkHN on April 5, 2024 | hide | past | favorite | 10 comments


> Excellent succinct breakdown of the xv mess

What xv[1] mess?

[1]: https://en.wikipedia.org/wiki/Xv_(software)


What's next, has xeyes been spying on us all this time?


That was a typo! Meant xz!


Xv is very nice.


Title violates HN submission guidelines.

The text is well-written, at that summary level necessarily leaving out many complicated details of the real "mess", but also all of the social aspects.


I'd say "Re: lcamtuf on the recent xz debacle" probably counts as a misleading title since the current post isn't by that user and the "Re" isn't enough to really make this clear. So the OP was probably ok to rewrite the title but probably editorialized it too much.

("Please use the original title, unless it is misleading or linkbait; don't editorialize." - https://news.ycombinator.com/newsguidelines.html)

If someone can suggest a more accurate and neutral title, preferably using some representative phrase from the article itself, we can change it.


Thanks for your reaction! Criticizing was easy, doing it better requires some thinking...

Maybe something like:

Openbsd's xz port maintainer looks at the build stages of the malicious code

I needed to reword the phrase in the article quite a bit to get under the length limit.


OK, let's use that above. Thanks!

(Submitted title was "Excellent succinct breakdown of the xv mess, from an OpenBSD developer")


> Title violates HN submission guidelines.

It's better to email hn@ycombinator.com when you see this, rather than just mention it in a comment.


Social aspects.. people were duped.. The end




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: