• 0 Posts
  • 317 Comments
Joined 1 year ago
cake
Cake day: July 29th, 2023

help-circle












  • Very annoying - the apparent author of the backdoor was in communication with me over several weeks trying to get xz 5.6.x added to Fedora 40 & 41 because of it’s “great new features”. We even worked with him to fix the valgrind issue (which it turns out now was caused by the backdoor he had added). We had to race last night to fix the problem after an inadvertent break of the embargo.

    He has been part of the xz project for 2 years, adding all sorts of binary test files, and to be honest with this level of sophistication I would be suspicious of even older versions of xz until proven otherwise.

    Damn. I would love to see a full post mortem on this compromise.


  • What the saying is trying to convey:

    Sometimes people focus on a few small details of some problem to such a great degree that they completely fail to consider the larger context and purpose.

    It isn’t trying to say details are unimportant. Only that the larger context matters and should be considered while investigating the details of a problem.

    I am trying to think of a good example. The one I found online is something like, “the senator was so focused on the wording of one subsection of the bill he didn’t stop to consider the bill was too unpopular to ever pass regardless of the wording”.

    Ok how about this. Let’s say a company is to unify access control across disparate systems. The overarching goal is to be able to set policy in one place not in each individual application.

    A team is in the process of evaluating a candidate product. They want to complete the evaluation in a set time frame and focus on a particular scenario (web app, specific tech stack) for a proof of concept that isn’t representative of many of the typical scenarios in the company (web, database, API, etc).

    The team spends their time focused on getting the evaluation done and discovers the product doesn’t integrate as well as originally expected with a key system. They focus on coming up with a solution so they can complete the proof of concept.

    They consider their efforts a success when they finish up the eval on time.

    But the evaluation wasn’t useful because it didn’t really consider the overarching project goals and in the end the solution didn’t even meet those goals!

    Hope this helps.






  • Hopefully my sarcasm was obvious.

    I swear people are just gladly diving headfirst into total despair. Any hint of good news? Shit all over it with a one liner as the guy above, trying to point out the hypocrisy as if the vacationer should just not fly back from the trip lol. Like jfc, would it kill you take the small W??

    People who see the effects of climate change (on the reef or whatever) with their own eyes are going to be a lot more likely to take climate change seriously and maybe take some real action – there’s a massive list of things we could be trying rather than being a doomer on social media. It’s not that hard to find activist groups, write govt representatives, etc. And fuck this idea that millions of people doing something won’t make a change lol. More learned helplessness.

    Not that we aren’t fucked… but how fucked we will be depends on what we do. Dooming on social media is guaranteed to not get it done.

    All it does is drains you of any motivation (or will to live) you might have had to do something, even if small.

    I’m just fucking sick of the constant despair-aganda and kind of want to tell people spreading it to shove it up their asses.