<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" encoding="UTF-8" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:sy="http://purl.org/rss/1.0/modules/syndication/" xmlns:admin="http://webns.net/mvcb/" xmlns:atom="http://www.w3.org/2005/Atom/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:googleplay="http://www.google.com/schemas/play-podcasts/1.0" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" xmlns:fireside="http://fireside.fm/modules/rss/fireside">
  <channel>
    <fireside:hostname>web01.fireside.fm</fireside:hostname>
    <fireside:genDate>Sat, 11 Apr 2026 07:52:59 -0500</fireside:genDate>
    <generator>Fireside (https://fireside.fm)</generator>
    <title>LINUX Unplugged - Episodes Tagged with “Jia Tan”</title>
    <link>https://linuxunplugged.com/tags/jia%20tan</link>
    <pubDate>Sun, 23 Jun 2024 18:15:00 -0700</pubDate>
    <description>An open show powered by community LINUX Unplugged takes the best attributes of open collaboration and turns it into a weekly show about Linux.
</description>
    <language>en-us</language>
    <itunes:type>episodic</itunes:type>
    <itunes:subtitle>Weekly Linux talk show with no script, no limits, surprise guests and tons of opinion.</itunes:subtitle>
    <itunes:author>Jupiter Broadcasting</itunes:author>
    <itunes:summary>An open show powered by community LINUX Unplugged takes the best attributes of open collaboration and turns it into a weekly show about Linux.
</itunes:summary>
    <itunes:image href="https://media24.fireside.fm/file/fireside-images-2024/podcasts/images/f/f31a453c-fa15-491f-8618-3f71f1d565e5/cover.jpg?v=3"/>
    <itunes:explicit>no</itunes:explicit>
    <itunes:owner>
      <itunes:name>Jupiter Broadcasting</itunes:name>
      <itunes:email>chris@jupiterbroadcasting.com</itunes:email>
    </itunes:owner>
<itunes:category text="Technology"/>
<itunes:category text="News">
  <itunes:category text="Tech News"/>
</itunes:category>
<item>
  <title>568: All Your Silos are Broken</title>
  <link>https://linuxunplugged.com/568</link>
  <guid isPermaLink="false">3cec6236-ba57-48be-b81a-5ded00bb79d5</guid>
  <pubDate>Sun, 23 Jun 2024 18:15:00 -0700</pubDate>
  <author>Jupiter Broadcasting</author>
  <enclosure url="https://aphid.fireside.fm/d/1437767933/f31a453c-fa15-491f-8618-3f71f1d565e5/3cec6236-ba57-48be-b81a-5ded00bb79d5.mp3" length="68080505" type="audio/mp3"/>
  <itunes:episodeType>full</itunes:episodeType>
  <itunes:author>Jupiter Broadcasting</itunes:author>
  <itunes:subtitle>Online identity is a ticking time bomb. Are trustworthy, open-source solutions ready to disarm it? Or will we be stuck with lackluster, proprietary systems?</itunes:subtitle>
  <itunes:duration>1:21:02</itunes:duration>
  <itunes:explicit>no</itunes:explicit>
  <itunes:image href="https://media24.fireside.fm/file/fireside-images-2024/podcasts/images/f/f31a453c-fa15-491f-8618-3f71f1d565e5/cover.jpg?v=3"/>
  <description>Online identity is a ticking time bomb. Are trustworthy, open-source solutions ready to disarm it? Or will we be stuck with lackluster, proprietary systems? 
</description>
  <itunes:keywords>Jupiter Broadcasting, Linux Podcast, Linux Unplugged, XZ Backdoor, Jia Tan, xz, xz utils, linux kernel, World Coin, commercial identity, ID, Nostr, Nostr Nook, BTC Prague, relays, notes and other stuff transmitted by relays, decentralized web, NIPs, web of trust, cryptography, PGP, GnuPG, OpenPGP, Lightning, ⚡, relevance glue, Highlighter, Satlantis, HiveTalk, zap.stream, ostrGit, Blogstack, Ditto, Wikifreedia, awesome-nostr, Amethyst, Primal, Nosta, yana, Ladybird, systemd, NixOS, Nix Drinking Game, TTS, Piper, text to speech, open source zealot, Stirling-PDF, sudo flame war, squid, systemd run0, ZSH, Starship, Distrobox, distrobox-assemble, Gathio</itunes:keywords>
  <content:encoded>
    <![CDATA[<p>Online identity is a ticking time bomb. Are trustworthy, open-source solutions ready to disarm it? Or will we be stuck with lackluster, proprietary systems?</p><p>Sponsored By:</p><ul><li><a rel="nofollow" href="https://jupitersignal.memberful.com/checkout?plan=52946&amp;coupon=summer">Core Contributor Membership</a>: <a rel="nofollow" href="https://jupitersignal.memberful.com/checkout?plan=52946&amp;coupon=summer">Take $1 a month of your membership for a lifetime! </a> Promo Code: summer</li><li><a rel="nofollow" href="http://tailscale.com/linuxunplugged">Tailscale</a>: <a rel="nofollow" href="http://tailscale.com/linuxunplugged">Tailscale is a programmable networking software that is private and secure by default - get it free on up to 100 devices!</a></li><li><a rel="nofollow" href="https://1password.com/unplugged">1Password Extended Access Management</a>: <a rel="nofollow" href="https://1password.com/unplugged">Secure every sign-in for every app on every device.</a></li></ul><p><a rel="payment" href="https://jupitersignal.memberful.com/checkout?plan=52946">Support LINUX Unplugged</a></p><p>Links:</p><ul><li><a title="💥 Gets Sats Quick and Easy with Strike" rel="nofollow" href="https://strike.me/">💥 Gets Sats Quick and Easy with Strike</a></li><li><a title="📻 LINUX Unplugged  on Fountain.FM" rel="nofollow" href="https://www.fountain.fm/show/dWiuBeqpDSM86AwXRXov">📻 LINUX Unplugged  on Fountain.FM</a></li><li><a title="Jupiter Broadcasting Meetups" rel="nofollow" href="https://www.meetup.com/jupiterbroadcasting/">Jupiter Broadcasting Meetups</a></li><li><a title="XZ Utils Backdoor Vulnerability (CVE-2024-3094): Comprehensive Guide" rel="nofollow" href="https://www.uptycs.com/blog/xz-utils-backdoor-vulnerability-cve-2024-3094">XZ Utils Backdoor Vulnerability (CVE-2024-3094): Comprehensive Guide</a></li><li><a title="The Mystery of ‘Jia Tan,’ the XZ Backdoor Mastermind" rel="nofollow" href="https://www.wired.com/story/jia-tan-xz-backdoor/">The Mystery of ‘Jia Tan,’ the XZ Backdoor Mastermind</a></li><li><a title="Who is ‘Jia Tan,’ the coder behind the XZ Utils Linux backdoor?" rel="nofollow" href="https://www.theverge.com/2024/4/3/24120244/who-is-jia-tan-the-coder-behind-the-xz-utils-linux-backdoor">Who is ‘Jia Tan,’ the coder behind the XZ Utils Linux backdoor?</a></li><li><a title="Reflections on Distrusting xz" rel="nofollow" href="https://news.ycombinator.com/item?id=39914981">Reflections on Distrusting xz</a></li><li><a title="The Linux kernel does not accept anonymous contributions due to legal reasons." rel="nofollow" href="https://news.ycombinator.com/item?id=17487801">The Linux kernel does not accept anonymous contributions due to legal reasons.</a> &mdash; The Linux kernel does not accept anonymous contributions due to legal reasons.</li><li><a title="Kernel.org Docs on contributions" rel="nofollow" href="https://www.kernel.org/doc/html/latest/process/1.Intro.html">Kernel.org Docs on contributions</a> &mdash; It is imperative that all code contributed to the kernel be legitimately free software.</li><li><a title="Elon Musk wants to ‘authenticate all real humans’ on Twitter." rel="nofollow" href="https://www.cnn.com/2022/04/28/tech/elon-musk-authenticate-all-real-humans/index.html">Elon Musk wants to ‘authenticate all real humans’ on Twitter.</a></li><li><a title="Elon Musk claims alien identity, links human brain function to AI purpose" rel="nofollow" href="https://www.livemint.com/technology/tech-news/elon-musk-claims-alien-identity-links-human-brain-function-to-ai-purpose-11716714971682.html">Elon Musk claims alien identity, links human brain function to AI purpose</a></li><li><a title="Elon Musk Finally Realizes That Verification Requires More Than A Credit Card, Planning To Make Users Upload Gov’t ID" rel="nofollow" href="https://www.techdirt.com/2023/08/22/elon-musk-finally-realizes-that-verification-requires-more-than-a-credit-card-planning-to-make-users-upload-govt-id/">Elon Musk Finally Realizes That Verification Requires More Than A Credit Card, Planning To Make Users Upload Gov’t ID</a></li><li><a title="Elon Musk can show the world how to really do ID" rel="nofollow" href="https://www.businessage.com/post/elon-musk-can-show-the-world-how-to-really-do-id">Elon Musk can show the world how to really do ID</a></li><li><a title="World ID" rel="nofollow" href="https://worldcoin.org/world-id">World ID</a></li><li><a title="Nostr: All Your Silos Are Broken" rel="nofollow" href="https://www.youtube.com/watch?v=SSFVR5ZXOuA">Nostr: All Your Silos Are Broken</a></li><li><a title="Nostr Iceberg Meme" rel="nofollow" href="https://miro.medium.com/v2/resize:fit:720/format:webp/0*Vq5EjPTk28SBl7Fn.jpeg">Nostr Iceberg Meme</a></li><li><a title="NIP-01" rel="nofollow" href="https://github.com/nostr-protocol/nips/blob/master/01.md">NIP-01</a></li><li><a title="Mapping Nostr keys to DNS-based internet identifiers" rel="nofollow" href="https://github.com/nostr-protocol/nips/blob/master/05.md">Mapping Nostr keys to DNS-based internet identifiers</a></li><li><a title="Navigating the social graph" rel="nofollow" href="https://pippellia.com/pippellia/Social+Graph/Navigating+the+social+graph">Navigating the social graph</a> &mdash; In this paper, you will find a definition of the social graph, principles for thinking about it, and practical ideas for using it for DoS prevention, social discovery, anti-impersonation, accurate ratings, and more.</li><li><a title="Highlighter" rel="nofollow" href="http://highlighter.com/">Highlighter</a> &mdash; Highlighter is like Substack &amp; Patreon but on Nostr.</li><li><a title="Satlantis" rel="nofollow" href="http://satlantis.io/">Satlantis</a> &mdash; Satlantis is like Trip Advisor, meets Instagram and Google Places.</li><li><a title="HiveTalk" rel="nofollow" href="https://hivetalk.org/">HiveTalk</a> &mdash; Free Video Calls, Messaging and Screen Sharing</li><li><a title="zap.stream" rel="nofollow" href="https://zap.stream/">zap.stream</a> &mdash; Twitch alt powered by value for value and Nostr</li><li><a title="ostrGit" rel="nofollow" href="https://github.com/NostrGit/NostrGit">ostrGit</a> &mdash; A truly censorship-resistant alternative to GitHub that has a chance of working.</li><li><a title="Blogstack" rel="nofollow" href="https://blogstack.io/">Blogstack</a> &mdash; Write decentralized blogs over relay using nostr w/ ⚡ lightning tips.</li><li><a title="Ditto" rel="nofollow" href="https://soapbox.pub/blog/announcing-ditto/">Ditto</a> &mdash; Ditto is a Nostr community server. It has a built-in Nostr relay, a web UI, and it implements Mastodon's REST API.</li><li><a title="UseNostr" rel="nofollow" href="https://usenostr.org/">UseNostr</a></li><li><a title="awesome-nostr" rel="nofollow" href="https://github.com/aljazceru/awesome-nostr">awesome-nostr</a></li><li><a title="Decentralized publishing for the web" rel="nofollow" href="https://nostr.how/en/what-is-nostr">Decentralized publishing for the web</a></li><li><a title="Nostr Apps" rel="nofollow" href="https://www.nostrapps.com/">Nostr Apps</a></li><li><a title="Nosta" rel="nofollow" href="https://nosta.me/">Nosta</a> &mdash; New to Nostr? You're in the right place. Here you can easily set up your profile, discover apps, and browse other profiles.</li><li><a title="Amethyst" rel="nofollow" href="https://www.nostrapps.com/apps/amethyst">Amethyst</a></li><li><a title="amethyst: Nostr client for Android" rel="nofollow" href="https://github.com/vitorpamplona/amethyst">amethyst: Nostr client for Android</a></li><li><a title="yana" rel="nofollow" href="https://github.com/frnandu/yana">yana</a></li><li><a title="Primal App" rel="nofollow" href="https://primal.net/downloads">Primal App</a></li><li><a title="Membership Summer Discount" rel="nofollow" href="https://jupitersignal.memberful.com/checkout?plan=52946&amp;coupon=summer">Membership Summer Discount</a> &mdash; Take $1 a month of your membership for a lifetime!</li><li><a title="SpeechNote" rel="nofollow" href="https://flathub.org/apps/net.mkiol.SpeechNote">SpeechNote</a> &mdash; Speech Note let you take, read and translate notes in multiple languages. It uses Speech to Text, Text to Speech and Machine Translation to do so.</li><li><a title="rhasspy/piper:" rel="nofollow" href="https://github.com/rhasspy/piper">rhasspy/piper:</a> &mdash; A fast, local neural text to speech system.</li><li><a title="Starship" rel="nofollow" href="https://starship.rs/">Starship</a> &mdash; The minimal, blazing-fast, and infinitely customizable prompt for any shell!</li><li><a title="starship on GitHub" rel="nofollow" href="https://github.com/starship/starship">starship on GitHub</a></li><li><a title="ZSH Docs: ZDOTDIR" rel="nofollow" href="https://zsh-manual.netlify.app/files?highlight=ZDOTDIR#51-startupshutdown-files">ZSH Docs: ZDOTDIR</a></li><li><a title="distrobox-assemble" rel="nofollow" href="https://github.com/89luca89/distrobox/blob/main/docs/usage/distrobox-assemble.md">distrobox-assemble</a> &mdash; distrobox-assemble takes care of creating or destroying containers in batches, based on a manifest file.</li><li><a title="Pick: Gathio" rel="nofollow" href="https://gath.io/">Pick: Gathio</a> &mdash; Gathio is a simple, federated, privacy-first event hosting platform.</li></ul>]]>
  </content:encoded>
  <itunes:summary>
    <![CDATA[<p>Online identity is a ticking time bomb. Are trustworthy, open-source solutions ready to disarm it? Or will we be stuck with lackluster, proprietary systems?</p><p>Sponsored By:</p><ul><li><a rel="nofollow" href="https://jupitersignal.memberful.com/checkout?plan=52946&amp;coupon=summer">Core Contributor Membership</a>: <a rel="nofollow" href="https://jupitersignal.memberful.com/checkout?plan=52946&amp;coupon=summer">Take $1 a month of your membership for a lifetime! </a> Promo Code: summer</li><li><a rel="nofollow" href="http://tailscale.com/linuxunplugged">Tailscale</a>: <a rel="nofollow" href="http://tailscale.com/linuxunplugged">Tailscale is a programmable networking software that is private and secure by default - get it free on up to 100 devices!</a></li><li><a rel="nofollow" href="https://1password.com/unplugged">1Password Extended Access Management</a>: <a rel="nofollow" href="https://1password.com/unplugged">Secure every sign-in for every app on every device.</a></li></ul><p><a rel="payment" href="https://jupitersignal.memberful.com/checkout?plan=52946">Support LINUX Unplugged</a></p><p>Links:</p><ul><li><a title="💥 Gets Sats Quick and Easy with Strike" rel="nofollow" href="https://strike.me/">💥 Gets Sats Quick and Easy with Strike</a></li><li><a title="📻 LINUX Unplugged  on Fountain.FM" rel="nofollow" href="https://www.fountain.fm/show/dWiuBeqpDSM86AwXRXov">📻 LINUX Unplugged  on Fountain.FM</a></li><li><a title="Jupiter Broadcasting Meetups" rel="nofollow" href="https://www.meetup.com/jupiterbroadcasting/">Jupiter Broadcasting Meetups</a></li><li><a title="XZ Utils Backdoor Vulnerability (CVE-2024-3094): Comprehensive Guide" rel="nofollow" href="https://www.uptycs.com/blog/xz-utils-backdoor-vulnerability-cve-2024-3094">XZ Utils Backdoor Vulnerability (CVE-2024-3094): Comprehensive Guide</a></li><li><a title="The Mystery of ‘Jia Tan,’ the XZ Backdoor Mastermind" rel="nofollow" href="https://www.wired.com/story/jia-tan-xz-backdoor/">The Mystery of ‘Jia Tan,’ the XZ Backdoor Mastermind</a></li><li><a title="Who is ‘Jia Tan,’ the coder behind the XZ Utils Linux backdoor?" rel="nofollow" href="https://www.theverge.com/2024/4/3/24120244/who-is-jia-tan-the-coder-behind-the-xz-utils-linux-backdoor">Who is ‘Jia Tan,’ the coder behind the XZ Utils Linux backdoor?</a></li><li><a title="Reflections on Distrusting xz" rel="nofollow" href="https://news.ycombinator.com/item?id=39914981">Reflections on Distrusting xz</a></li><li><a title="The Linux kernel does not accept anonymous contributions due to legal reasons." rel="nofollow" href="https://news.ycombinator.com/item?id=17487801">The Linux kernel does not accept anonymous contributions due to legal reasons.</a> &mdash; The Linux kernel does not accept anonymous contributions due to legal reasons.</li><li><a title="Kernel.org Docs on contributions" rel="nofollow" href="https://www.kernel.org/doc/html/latest/process/1.Intro.html">Kernel.org Docs on contributions</a> &mdash; It is imperative that all code contributed to the kernel be legitimately free software.</li><li><a title="Elon Musk wants to ‘authenticate all real humans’ on Twitter." rel="nofollow" href="https://www.cnn.com/2022/04/28/tech/elon-musk-authenticate-all-real-humans/index.html">Elon Musk wants to ‘authenticate all real humans’ on Twitter.</a></li><li><a title="Elon Musk claims alien identity, links human brain function to AI purpose" rel="nofollow" href="https://www.livemint.com/technology/tech-news/elon-musk-claims-alien-identity-links-human-brain-function-to-ai-purpose-11716714971682.html">Elon Musk claims alien identity, links human brain function to AI purpose</a></li><li><a title="Elon Musk Finally Realizes That Verification Requires More Than A Credit Card, Planning To Make Users Upload Gov’t ID" rel="nofollow" href="https://www.techdirt.com/2023/08/22/elon-musk-finally-realizes-that-verification-requires-more-than-a-credit-card-planning-to-make-users-upload-govt-id/">Elon Musk Finally Realizes That Verification Requires More Than A Credit Card, Planning To Make Users Upload Gov’t ID</a></li><li><a title="Elon Musk can show the world how to really do ID" rel="nofollow" href="https://www.businessage.com/post/elon-musk-can-show-the-world-how-to-really-do-id">Elon Musk can show the world how to really do ID</a></li><li><a title="World ID" rel="nofollow" href="https://worldcoin.org/world-id">World ID</a></li><li><a title="Nostr: All Your Silos Are Broken" rel="nofollow" href="https://www.youtube.com/watch?v=SSFVR5ZXOuA">Nostr: All Your Silos Are Broken</a></li><li><a title="Nostr Iceberg Meme" rel="nofollow" href="https://miro.medium.com/v2/resize:fit:720/format:webp/0*Vq5EjPTk28SBl7Fn.jpeg">Nostr Iceberg Meme</a></li><li><a title="NIP-01" rel="nofollow" href="https://github.com/nostr-protocol/nips/blob/master/01.md">NIP-01</a></li><li><a title="Mapping Nostr keys to DNS-based internet identifiers" rel="nofollow" href="https://github.com/nostr-protocol/nips/blob/master/05.md">Mapping Nostr keys to DNS-based internet identifiers</a></li><li><a title="Navigating the social graph" rel="nofollow" href="https://pippellia.com/pippellia/Social+Graph/Navigating+the+social+graph">Navigating the social graph</a> &mdash; In this paper, you will find a definition of the social graph, principles for thinking about it, and practical ideas for using it for DoS prevention, social discovery, anti-impersonation, accurate ratings, and more.</li><li><a title="Highlighter" rel="nofollow" href="http://highlighter.com/">Highlighter</a> &mdash; Highlighter is like Substack &amp; Patreon but on Nostr.</li><li><a title="Satlantis" rel="nofollow" href="http://satlantis.io/">Satlantis</a> &mdash; Satlantis is like Trip Advisor, meets Instagram and Google Places.</li><li><a title="HiveTalk" rel="nofollow" href="https://hivetalk.org/">HiveTalk</a> &mdash; Free Video Calls, Messaging and Screen Sharing</li><li><a title="zap.stream" rel="nofollow" href="https://zap.stream/">zap.stream</a> &mdash; Twitch alt powered by value for value and Nostr</li><li><a title="ostrGit" rel="nofollow" href="https://github.com/NostrGit/NostrGit">ostrGit</a> &mdash; A truly censorship-resistant alternative to GitHub that has a chance of working.</li><li><a title="Blogstack" rel="nofollow" href="https://blogstack.io/">Blogstack</a> &mdash; Write decentralized blogs over relay using nostr w/ ⚡ lightning tips.</li><li><a title="Ditto" rel="nofollow" href="https://soapbox.pub/blog/announcing-ditto/">Ditto</a> &mdash; Ditto is a Nostr community server. It has a built-in Nostr relay, a web UI, and it implements Mastodon's REST API.</li><li><a title="UseNostr" rel="nofollow" href="https://usenostr.org/">UseNostr</a></li><li><a title="awesome-nostr" rel="nofollow" href="https://github.com/aljazceru/awesome-nostr">awesome-nostr</a></li><li><a title="Decentralized publishing for the web" rel="nofollow" href="https://nostr.how/en/what-is-nostr">Decentralized publishing for the web</a></li><li><a title="Nostr Apps" rel="nofollow" href="https://www.nostrapps.com/">Nostr Apps</a></li><li><a title="Nosta" rel="nofollow" href="https://nosta.me/">Nosta</a> &mdash; New to Nostr? You're in the right place. Here you can easily set up your profile, discover apps, and browse other profiles.</li><li><a title="Amethyst" rel="nofollow" href="https://www.nostrapps.com/apps/amethyst">Amethyst</a></li><li><a title="amethyst: Nostr client for Android" rel="nofollow" href="https://github.com/vitorpamplona/amethyst">amethyst: Nostr client for Android</a></li><li><a title="yana" rel="nofollow" href="https://github.com/frnandu/yana">yana</a></li><li><a title="Primal App" rel="nofollow" href="https://primal.net/downloads">Primal App</a></li><li><a title="Membership Summer Discount" rel="nofollow" href="https://jupitersignal.memberful.com/checkout?plan=52946&amp;coupon=summer">Membership Summer Discount</a> &mdash; Take $1 a month of your membership for a lifetime!</li><li><a title="SpeechNote" rel="nofollow" href="https://flathub.org/apps/net.mkiol.SpeechNote">SpeechNote</a> &mdash; Speech Note let you take, read and translate notes in multiple languages. It uses Speech to Text, Text to Speech and Machine Translation to do so.</li><li><a title="rhasspy/piper:" rel="nofollow" href="https://github.com/rhasspy/piper">rhasspy/piper:</a> &mdash; A fast, local neural text to speech system.</li><li><a title="Starship" rel="nofollow" href="https://starship.rs/">Starship</a> &mdash; The minimal, blazing-fast, and infinitely customizable prompt for any shell!</li><li><a title="starship on GitHub" rel="nofollow" href="https://github.com/starship/starship">starship on GitHub</a></li><li><a title="ZSH Docs: ZDOTDIR" rel="nofollow" href="https://zsh-manual.netlify.app/files?highlight=ZDOTDIR#51-startupshutdown-files">ZSH Docs: ZDOTDIR</a></li><li><a title="distrobox-assemble" rel="nofollow" href="https://github.com/89luca89/distrobox/blob/main/docs/usage/distrobox-assemble.md">distrobox-assemble</a> &mdash; distrobox-assemble takes care of creating or destroying containers in batches, based on a manifest file.</li><li><a title="Pick: Gathio" rel="nofollow" href="https://gath.io/">Pick: Gathio</a> &mdash; Gathio is a simple, federated, privacy-first event hosting platform.</li></ul>]]>
  </itunes:summary>
</item>
<item>
  <title>556: The xz Backdoor Exposed 🚨</title>
  <link>https://linuxunplugged.com/556</link>
  <guid isPermaLink="false">5b666786-1220-4fe6-9d6f-b6ef537a3fe3</guid>
  <pubDate>Sun, 31 Mar 2024 18:00:00 -0700</pubDate>
  <author>Jupiter Broadcasting</author>
  <enclosure url="https://aphid.fireside.fm/d/1437767933/f31a453c-fa15-491f-8618-3f71f1d565e5/5b666786-1220-4fe6-9d6f-b6ef537a3fe3.mp3" length="58846585" type="audio/mp3"/>
  <itunes:episodeType>full</itunes:episodeType>
  <itunes:author>Jupiter Broadcasting</itunes:author>
  <itunes:subtitle>We're breaking down the attack: how it works, how it was hidden, and why time was running out for the attacker.</itunes:subtitle>
  <itunes:duration>1:10:03</itunes:duration>
  <itunes:explicit>no</itunes:explicit>
  <itunes:image href="https://media24.fireside.fm/file/fireside-images-2024/podcasts/images/f/f31a453c-fa15-491f-8618-3f71f1d565e5/cover.jpg?v=3"/>
  <description>We're breaking down the attack: how it works, how it was hidden, and why time was running out for the attacker. 
</description>
  <itunes:keywords>Jupiter Broadcasting, Linux Podcast, Linux Unplugged, xz, backdoor, remote code execution, OpenSSH, Debian, Fedora, Ubuntu, Kali Linux, Arch Linux, Gentoo, openSUSE, Alpine, NixOS, Jia Tan, trust model, burnout, systemd, transparency, open source, HUMINT, compression libraries,</itunes:keywords>
  <content:encoded>
    <![CDATA[<p>We&#39;re breaking down the attack: how it works, how it was hidden, and why time was running out for the attacker.</p><p>Sponsored By:</p><ul><li><a rel="nofollow" href="http://tailscale.com/linuxunplugged">Tailscale</a>: <a rel="nofollow" href="http://tailscale.com/linuxunplugged">Tailscale is a programmable networking software that is private and secure by default - get it free on up to 100 devices!</a></li><li><a rel="nofollow" href="https://1password.com/unplugged">1Password Extended Access Management</a>: <a rel="nofollow" href="https://1password.com/unplugged">Secure every sign-in for every app on every device.</a></li></ul><p><a rel="payment" href="https://jupitersignal.memberful.com/checkout?plan=52946">Support LINUX Unplugged</a></p><p>Links:</p><ul><li><a title="💥 Gets Sats Quick and Easy with Strike" rel="nofollow" href="https://strike.me/">💥 Gets Sats Quick and Easy with Strike</a></li><li><a title="📻 LINUX Unplugged on Fountain.FM" rel="nofollow" href="https://www.fountain.fm/show/dWiuBeqpDSM86AwXRXov">📻 LINUX Unplugged on Fountain.FM</a></li><li><a title="oss-security mailing list" rel="nofollow" href="https://www.openwall.com/lists/oss-security/2024/03/29/4">oss-security mailing list</a> &mdash; Backdoor in upstream xz/liblzma leading to ssh server compromise.
</li><li><a title="Fedora Announcement" rel="nofollow" href="https://www.redhat.com/en/blog/urgent-security-alert-fedora-41-and-rawhide-users">Fedora Announcement</a></li><li><a title="Debian Announcement" rel="nofollow" href="https://security-tracker.debian.org/tracker/CVE-2024-3094">Debian Announcement</a></li><li><a title="Ubuntu Announcement" rel="nofollow" href="https://discourse.ubuntu.com/t/xz-liblzma-security-update/43714">Ubuntu Announcement</a></li><li><a title="Kali Linux Announcement" rel="nofollow" href="https://www.kali.org/blog/about-the-xz-backdoor/">Kali Linux Announcement</a></li><li><a title="Arch Linux Announcement" rel="nofollow" href="https://archlinux.org/news/the-xz-package-has-been-backdoored/">Arch Linux Announcement</a></li><li><a title="Gentoo Announcement" rel="nofollow" href="https://bugs.gentoo.org/928134">Gentoo Announcement</a></li><li><a title="openSUSE Tumbleweeed Announcement" rel="nofollow" href="https://news.opensuse.org/2024/03/29/xz-backdoor/">openSUSE Tumbleweeed Announcement</a></li><li><a title="NixOS Unstable Discussion" rel="nofollow" href="https://discourse.nixos.org/t/cve-2024-3094-malicious-code-in-xz-5-6-0-and-5-6-1-tarballs/42405">NixOS Unstable Discussion</a></li><li><a title="Why does it take two weeks for NixOS to replace xz?" rel="nofollow" href="https://discourse.nixos.org/t/cve-2024-3094-malicious-code-in-xz-5-6-0-and-5-6-1-tarballs/42405/5">Why does it take two weeks for NixOS to replace xz?</a></li><li><a title="Andres Freund on Mastodon" rel="nofollow" href="https://mastodon.social/@AndresFreundTec/112180406142695845">Andres Freund on Mastodon</a> &mdash; I was doing some micro-benchmarking at the time, needed to quiesce the system to reduce noise. Saw sshd processes were using a surprising amount of CPU, despite immediately failing because of wrong usernames etc....
</li><li><a title="rwmj on Hacker News" rel="nofollow" href="https://news.ycombinator.com/item?id=39865810">rwmj on Hacker News</a> &mdash; Very annoying - the apparent author of the backdoor was in communication with me over several weeks trying to get xz 5.6.x added to Fedora 40 &amp; 41 because of its "great new features"
</li><li><a title="A Microcosm of the interactions in Open Source projects" rel="nofollow" href="https://robmensching.com/blog/posts/2024/03/30/a-microcosm-of-the-interactions-in-open-source-projects/">A Microcosm of the interactions in Open Source projects</a> &mdash; Make no mistake. This is the way it works. It needs to change.
</li><li><a title="Devuan GNU/Linux on X" rel="nofollow" href="https://twitter.com/devuanorg/status/1774029432979653069?t=ASJqAbm5fVHDKeq7CLKqjw">Devuan GNU/Linux on X</a> &mdash; Devuan is not affected by the latest vulnerability caused by systemd.
</li><li><a title="systemd PR: Dynamically load compression libraries" rel="nofollow" href="https://github.com/systemd/systemd/pull/31550#issuecomment-1972737923">systemd PR: Dynamically load compression libraries</a></li><li><a title="Matteo Croce on X" rel="nofollow" href="https://twitter.com/teknoraver85/status/1774452847188312163">Matteo Croce on X</a> &mdash; I'm the author of such PR. While I absolutely didn't know that libxz had a backdoor, I really think that libraries should be loaded on-demand when rarely used, hence my change :)
</li><li><a title="Ryan C. Gordon on X" rel="nofollow" href="https://twitter.com/icculus/status/1774310925035524333">Ryan C. Gordon on X</a> &mdash; This is probably how the xz thing happened, right?
</li><li><a title="Jan Wildeboer on the Fediverse" rel="nofollow" href="https://social.wildeboer.net/@jwildeboer/112184074379919145">Jan Wildeboer on the Fediverse</a> &mdash; Again the FOSS world has proven to be vigilant and proactive in finding bugs and backdoors, IMHO.</li><li><a title="Unplugged Core Membership" rel="nofollow" href="https://unpluggedcore.com/">Unplugged Core Membership</a></li><li><a title="TXLF is coming up! " rel="nofollow" href="https://2024.texaslinuxfest.org/">TXLF is coming up! </a> &mdash; April 12 - 13 in Austin, Texas.
</li><li><a title="LFNW coming up!" rel="nofollow" href="https://linuxfestnorthwest.org/">LFNW coming up!</a> &mdash; April 26 - 28
</li><li><a title="Mobile Game Ads Are Boosting Podcast Follower Counts" rel="nofollow" href="https://www.bloomberg.com/news/newsletters/2024-03-28/mobile-game-ads-are-boosting-podcast-follower-counts">Mobile Game Ads Are Boosting Podcast Follower Counts</a> &mdash; Wondery, iHeart and Lemonada Media are all using a non-public product from MowPod - which gives extra lives and game credits to gamers if they follow shows on Apple Podcasts from game apps.
</li><li><a title="MowPod&#39;s podcast promotion tools: tales from the bar" rel="nofollow" href="https://podnews.net/article/mowpod-promotion">MowPod's podcast promotion tools: tales from the bar</a></li><li><a title="fortydeux&#39;s NixOS Configs" rel="nofollow" href="https://github.com/fortydeux/Fortydeux-NixOS-System-Flake/">fortydeux's NixOS Configs</a></li><li><a title="Prism Launcher" rel="nofollow" href="https://prismlauncher.org/">Prism Launcher</a> &mdash; An Open Source Minecraft launcher with the ability to manage multiple instances, accounts and mods.
</li><li><a title="World Backup Day — March 31st" rel="nofollow" href="https://www.worldbackupday.com/en/">World Backup Day — March 31st</a> &mdash; One small accident or failure could destroy all the important stuff you care about.
</li><li><a title="Updating Our Fiddly Bits | LINUX Unplugged 494" rel="nofollow" href="https://www.jupiterbroadcasting.com/show/linux-unplugged/494/">Updating Our Fiddly Bits | LINUX Unplugged 494</a></li></ul>]]>
  </content:encoded>
  <itunes:summary>
    <![CDATA[<p>We&#39;re breaking down the attack: how it works, how it was hidden, and why time was running out for the attacker.</p><p>Sponsored By:</p><ul><li><a rel="nofollow" href="http://tailscale.com/linuxunplugged">Tailscale</a>: <a rel="nofollow" href="http://tailscale.com/linuxunplugged">Tailscale is a programmable networking software that is private and secure by default - get it free on up to 100 devices!</a></li><li><a rel="nofollow" href="https://1password.com/unplugged">1Password Extended Access Management</a>: <a rel="nofollow" href="https://1password.com/unplugged">Secure every sign-in for every app on every device.</a></li></ul><p><a rel="payment" href="https://jupitersignal.memberful.com/checkout?plan=52946">Support LINUX Unplugged</a></p><p>Links:</p><ul><li><a title="💥 Gets Sats Quick and Easy with Strike" rel="nofollow" href="https://strike.me/">💥 Gets Sats Quick and Easy with Strike</a></li><li><a title="📻 LINUX Unplugged on Fountain.FM" rel="nofollow" href="https://www.fountain.fm/show/dWiuBeqpDSM86AwXRXov">📻 LINUX Unplugged on Fountain.FM</a></li><li><a title="oss-security mailing list" rel="nofollow" href="https://www.openwall.com/lists/oss-security/2024/03/29/4">oss-security mailing list</a> &mdash; Backdoor in upstream xz/liblzma leading to ssh server compromise.
</li><li><a title="Fedora Announcement" rel="nofollow" href="https://www.redhat.com/en/blog/urgent-security-alert-fedora-41-and-rawhide-users">Fedora Announcement</a></li><li><a title="Debian Announcement" rel="nofollow" href="https://security-tracker.debian.org/tracker/CVE-2024-3094">Debian Announcement</a></li><li><a title="Ubuntu Announcement" rel="nofollow" href="https://discourse.ubuntu.com/t/xz-liblzma-security-update/43714">Ubuntu Announcement</a></li><li><a title="Kali Linux Announcement" rel="nofollow" href="https://www.kali.org/blog/about-the-xz-backdoor/">Kali Linux Announcement</a></li><li><a title="Arch Linux Announcement" rel="nofollow" href="https://archlinux.org/news/the-xz-package-has-been-backdoored/">Arch Linux Announcement</a></li><li><a title="Gentoo Announcement" rel="nofollow" href="https://bugs.gentoo.org/928134">Gentoo Announcement</a></li><li><a title="openSUSE Tumbleweeed Announcement" rel="nofollow" href="https://news.opensuse.org/2024/03/29/xz-backdoor/">openSUSE Tumbleweeed Announcement</a></li><li><a title="NixOS Unstable Discussion" rel="nofollow" href="https://discourse.nixos.org/t/cve-2024-3094-malicious-code-in-xz-5-6-0-and-5-6-1-tarballs/42405">NixOS Unstable Discussion</a></li><li><a title="Why does it take two weeks for NixOS to replace xz?" rel="nofollow" href="https://discourse.nixos.org/t/cve-2024-3094-malicious-code-in-xz-5-6-0-and-5-6-1-tarballs/42405/5">Why does it take two weeks for NixOS to replace xz?</a></li><li><a title="Andres Freund on Mastodon" rel="nofollow" href="https://mastodon.social/@AndresFreundTec/112180406142695845">Andres Freund on Mastodon</a> &mdash; I was doing some micro-benchmarking at the time, needed to quiesce the system to reduce noise. Saw sshd processes were using a surprising amount of CPU, despite immediately failing because of wrong usernames etc....
</li><li><a title="rwmj on Hacker News" rel="nofollow" href="https://news.ycombinator.com/item?id=39865810">rwmj on Hacker News</a> &mdash; Very annoying - the apparent author of the backdoor was in communication with me over several weeks trying to get xz 5.6.x added to Fedora 40 &amp; 41 because of its "great new features"
</li><li><a title="A Microcosm of the interactions in Open Source projects" rel="nofollow" href="https://robmensching.com/blog/posts/2024/03/30/a-microcosm-of-the-interactions-in-open-source-projects/">A Microcosm of the interactions in Open Source projects</a> &mdash; Make no mistake. This is the way it works. It needs to change.
</li><li><a title="Devuan GNU/Linux on X" rel="nofollow" href="https://twitter.com/devuanorg/status/1774029432979653069?t=ASJqAbm5fVHDKeq7CLKqjw">Devuan GNU/Linux on X</a> &mdash; Devuan is not affected by the latest vulnerability caused by systemd.
</li><li><a title="systemd PR: Dynamically load compression libraries" rel="nofollow" href="https://github.com/systemd/systemd/pull/31550#issuecomment-1972737923">systemd PR: Dynamically load compression libraries</a></li><li><a title="Matteo Croce on X" rel="nofollow" href="https://twitter.com/teknoraver85/status/1774452847188312163">Matteo Croce on X</a> &mdash; I'm the author of such PR. While I absolutely didn't know that libxz had a backdoor, I really think that libraries should be loaded on-demand when rarely used, hence my change :)
</li><li><a title="Ryan C. Gordon on X" rel="nofollow" href="https://twitter.com/icculus/status/1774310925035524333">Ryan C. Gordon on X</a> &mdash; This is probably how the xz thing happened, right?
</li><li><a title="Jan Wildeboer on the Fediverse" rel="nofollow" href="https://social.wildeboer.net/@jwildeboer/112184074379919145">Jan Wildeboer on the Fediverse</a> &mdash; Again the FOSS world has proven to be vigilant and proactive in finding bugs and backdoors, IMHO.</li><li><a title="Unplugged Core Membership" rel="nofollow" href="https://unpluggedcore.com/">Unplugged Core Membership</a></li><li><a title="TXLF is coming up! " rel="nofollow" href="https://2024.texaslinuxfest.org/">TXLF is coming up! </a> &mdash; April 12 - 13 in Austin, Texas.
</li><li><a title="LFNW coming up!" rel="nofollow" href="https://linuxfestnorthwest.org/">LFNW coming up!</a> &mdash; April 26 - 28
</li><li><a title="Mobile Game Ads Are Boosting Podcast Follower Counts" rel="nofollow" href="https://www.bloomberg.com/news/newsletters/2024-03-28/mobile-game-ads-are-boosting-podcast-follower-counts">Mobile Game Ads Are Boosting Podcast Follower Counts</a> &mdash; Wondery, iHeart and Lemonada Media are all using a non-public product from MowPod - which gives extra lives and game credits to gamers if they follow shows on Apple Podcasts from game apps.
</li><li><a title="MowPod&#39;s podcast promotion tools: tales from the bar" rel="nofollow" href="https://podnews.net/article/mowpod-promotion">MowPod's podcast promotion tools: tales from the bar</a></li><li><a title="fortydeux&#39;s NixOS Configs" rel="nofollow" href="https://github.com/fortydeux/Fortydeux-NixOS-System-Flake/">fortydeux's NixOS Configs</a></li><li><a title="Prism Launcher" rel="nofollow" href="https://prismlauncher.org/">Prism Launcher</a> &mdash; An Open Source Minecraft launcher with the ability to manage multiple instances, accounts and mods.
</li><li><a title="World Backup Day — March 31st" rel="nofollow" href="https://www.worldbackupday.com/en/">World Backup Day — March 31st</a> &mdash; One small accident or failure could destroy all the important stuff you care about.
</li><li><a title="Updating Our Fiddly Bits | LINUX Unplugged 494" rel="nofollow" href="https://www.jupiterbroadcasting.com/show/linux-unplugged/494/">Updating Our Fiddly Bits | LINUX Unplugged 494</a></li></ul>]]>
  </itunes:summary>
</item>
  </channel>
</rss>
