Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Currently if you visit the xz repository it is disabled for violating github's TOS.

While it should clearly be disabled, I feel like github should leave the code and history up, while displaying a banner (and disabled any features that could be exploited), so that researchers and others can learn about the exploit.

In more minor situations when a library is hosting malicious code, if I found the repo to be down I might not think anything of it.



I imagine they don’t want automation downloading it.


You can find GitHub events from the repo as a csv here https://github.com/emirkmo/xz-backdoor-github

If you are interested in the source code that is easy to find. This code and git repo are linked all over the world, in many git repos, and the source is bundled many times in releases as well.


xz has its own git mirror where you can see all the commits


Notably only writable by Lasse who I personally believe is a Good Actor here.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: