Aman Bhargava
amanbhargava.com
Aman Bhargava
@amanbhargava.com
Reposted by Aman Bhargava
you're an adult you can just take performance enhancing drugs. there's no international doping agency for Jira sprints

"cheating is unfair"
why?
"cheating creates losers"

You have to use Jira, Devin. you are the loser
October 27, 2024 at 11:49 AM
Reposted by Aman Bhargava
This might be the best executed supply chain attack we've seen described in the open, and it's a nightmare scenario: malicious, competent, authorized upstream in a widely used library.

Looks like this got caught by chance. Wonder how long it would have taken otherwise.
Woah. Backdoor in liblzma targeting ssh servers.

www.openwall.com/lists/oss-se...

It has everything: malicious upstream, masterful obfuscation, detection due to performance degradation, inclusion in OpenSSH via distro patches for systemd support…

Now I’m curious what it does in RSA_public_decrypt
oss-security - backdoor in upstream xz/liblzma leading to ssh server compromise
www.openwall.com
March 29, 2024 at 7:29 PM