proomt

Search

Search posts, papers, and topics

All posts

Lobsters

Infecting the Steam Link with NixOS

Related reading

  1. Trusting-Trust Attack against an Entire Linux Distribution through Binary Manipulation

    The authors show that the classic trusting‑trust attack is not limited to compilers: by tampering with GNU strip they can inject a payload that propagates through NixOS's bootstrap and ends up in almost every binary of the final system. The attack succeeds on a real nixpkgs revision, building a full graphical installer while backdooring the majority of its binaries.

    arXiv cs.SE (Software Engineering)arxiv.org1 minpaperHN24159
  2. The xz backdoor disclosure

    Upstream xz 5.6.0/5.6.1 tarballs were compromised with an obfuscated script that modifies liblzma to inject a backdoor, which activates on specific x86_64 Linux builds and slows SSH logins. The issue is reproducible, detectable via source checks, and mitigated by avoiding the tainted releases or rebuilding from a clean source.

    Hall of Fameopenwall.com8 minpostmortemHN45491849