Discussion
Loading...

Post

Log in
  • About
  • Code of conduct
  • Privacy
  • Users
  • Instances
  • About Bonfire
daniel:// stenberg://
daniel:// stenberg://
@bagder@mastodon.social  ·  activity timestamp 2 days ago

I found this Veratasium documentary on the xz Jia Tan backdoor adventure quite good and surprisingly detailed:

https://www.youtube.com/watch?v=aoag03mSuXQ

Auf YouTube findest du die angesagtesten Videos und Tracks. Außerdem kannst du eigene Inhalte hochladen und mit Freunden oder gleich der ganzen Welt teilen.
  • Copy link
  • Flag this post
  • Block
jer
jer
@jerrej@mastodon.social  ·  activity timestamp 2 days ago

@bagder

Shame about the #clickbait title, but I guess Veritasium wants that money and that's fine.

  • Copy link
  • Flag this comment
  • Block
petur 😶🇺🇦🇵🇸🇹🇼
petur 😶🇺🇦🇵🇸🇹🇼
@peturdainn@mastodon.social  ·  activity timestamp 2 days ago

@bagder I had up to now never seen the colour mixing analogy, quite like that.

Also, does this count as a rickroll?

  • Copy link
  • Flag this comment
  • Block
Renke Meuwese
Renke Meuwese
@meuwese@mastodon.social  ·  activity timestamp 2 days ago

@bagder I learned more than I would care to admit about how encryption works. And the RedHat admin was admirably candid about his role.

  • Copy link
  • Flag this comment
  • Block
Denzel
Denzel
@FarmerDenzel@infosec.exchange  ·  activity timestamp 2 days ago

@bagder I actually spent some time talking through the technical details of the backdoor with the writers of that video, since they came across my talk about it just after it was discovered.

I definitely think the video is a bit dramatic and geared towards a less technical (or at least less cyber-focused) audience, but was impressed with how much they cared about getting the minutiae right. Realistically, most of their viewers won’t care about ifunc or dynamic linker audit hooks, but it does keep things interesting for the cyber folks watching.

  • Copy link
  • Flag this comment
  • Block
daniel:// stenberg://
daniel:// stenberg://
@bagder@mastodon.social  ·  activity timestamp 2 days ago

@FarmerDenzel yeah, I would probably even argue that they made it a little *too* detailed at the risk of getting people bored for a show geared towards "common people"

  • Copy link
  • Flag this comment
  • Block
Jim Fuller
Jim Fuller
@jimfuller@mastodon.social  ·  activity timestamp 2 days ago

@bagder still gives me the shivers ....

  • Copy link
  • Flag this comment
  • Block
daniel:// stenberg://
daniel:// stenberg://
@bagder@mastodon.social  ·  activity timestamp 2 days ago

@jimfuller yeah! it's a good reminder to walk through the steps we have to make us not become part of a future similar documentary...

  • Copy link
  • Flag this comment
  • Block
Jim Fuller
Jim Fuller
@jimfuller@mastodon.social  ·  activity timestamp 2 days ago

@bagder I might have a new simulation for curl up this year ;)

  • Copy link
  • Flag this comment
  • Block

bonfire.cafe

A space for Bonfire maintainers and contributors to communicate

bonfire.cafe: About · Code of conduct · Privacy · Users · Instances
Bonfire social · 1.0.2-alpha.34 no JS en
Automatic federation enabled
Log in
Instance logo
  • Explore
  • About
  • Members
  • Code of Conduct