tukaani-project

By tukaani-project

Tukaani-project Alternatives

Similar projects and alternatives to tukaani-project

NOTE: The number of mentions on this list indicates mentions on common posts plus user suggested alternatives. Hence, a higher number means a better tukaani-project alternative or higher similarity.

tukaani-project reviews and mentions

Posts with mentions or reviews of tukaani-project. We have used some of these posts to build our list of alternatives and similar projects. The last one was on 2024-03-29.
  • Backdoor in upstream xz/liblzma leading to SSH server compromise
    49 projects | news.ycombinator.com | 29 Mar 2024
    Thank you. If you wouldn't have explained the background, I totally would've thought that this is just an innocent typo.

    (I still think it's like... 60% a typo? don't know)

    Anyhow, other people called the CCing of JiaT75 by Lasse suspicious:

    https://news.ycombinator.com/item?id=39867593

    https://lore.kernel.org/lkml/20240320183846.19475-2-lasse.co...

    Someone pointed out the "mental health issues" and "some other things"

    https://news.ycombinator.com/item?id=39868881

    https://www.mail-archive.com/[email protected]/msg00567.h...

    Lasse is of course a Nordic name, and the whole project has a finnish name and hosting

    https://news.ycombinator.com/item?id=39866902

    If I wanted to go rogue and insert a backdoor in a project of mine, I'd probably create a new sockpuppet account and hand over management of the project to them. The above is worringly compatible with this hypothesis.

    OTOH, JiaT75 did not reuse the existing hosting provider, but rather switched the site to github.io and uploaded there old tarballs:

    https://github.com/tukaani-project/tukaani-project.github.io...

    If JiaT75 is an old-timer in the project, wouldn't they have kept using the same hosting infra?

    There are also some other grim possibilities: someone forced Lasse to hand over the project (violence or blackmailing? as farfetched as that sounds)... or maybe stole Lasse devices (and identity?) and now Lasse is incapacitated?

    Or maybe it's just some other fellow scandinavian who pretends to be chinese and got Lasse's trust.

    Is the same person sockpuppeting Hans Jansen? It's amusing (but unsurprising) that they are using both german-sounding and chinese-sounding identities.

    That said, I don't think it's unreasonable to think that Lasse genuinely trusted JiaT75, genuinely believed that the ifunc stuff was reasonable (it probably isn't: https://news.ycombinator.com/item?id=39869538 ) and handed over the project to them.

    And at the end of the day, the only thing linking JiaT75 is a swedish/finnish racist joke which could well be a typo. People already checked the timezone of the commits, but I wonder if anyone has already checked the time-of-day of those commits... does it actually match the working hours that a person genuinely living (and sleeping) in China would follow?

Stats

Basic tukaani-project repo stats
5
-
-
-

Sponsored
SaaSHub - Software Alternatives and Reviews
SaaSHub helps you find the best software and product alternatives
www.saashub.com