Backdoor found in widely used Linux utility breaks encrypted SSH connections | Ars Technica
Backdoor found in widely used Linux utility breaks encrypted SSH connections | Ars Technica

Backdoor found in widely used Linux utility breaks encrypted SSH connections

TL;DR there was a backdoor found in the XZ program. All major distros have been updated but it is recommended that you do a fresh install on systems that are exposed to the internet and that had the bad version of the program. Only upstream distros were affected.
Don't tell me how to live my life, Ars Technica.
"stable" release of Arch?
They mean a variant you use in a stable, like to run an automatic feeder for horses. According to Ars Technica, however, you are not to use it in your production stable.
yes, like my marriage
I am not deep enough in it, but from the arch-announce mailinglist:
https://www.openwall.com/lists/oss-security/2024/03/29/4
You should not run Arch in production. Boom, I said it
Well I don't see any cops.
Ars Technica sounds like a weirdo to me these days. Loves to attack big techs (although understandable), now adds this to their description of Arch.