social.coop is one of the many independent Mastodon servers you can use to participate in the fediverse.
A Fediverse instance for people interested in cooperative and collective projects. If you are interested in joining our community, please apply at https://join.social.coop/registration-form.html.

Administered by:

Server stats:

489
active users

#xz

3 posts3 participants0 posts today
Replied in thread

@OS1337 @Yuki @bjornsdottirs well, it does work given aggressive #xz compression.

Problem is rather to shove more on a 1440kB FDD than initramfs+kernel.

Tho a bootfloppy w/ #syslinux that then bootstraps multiple splitted initramfs parts in RAM from multiple disks should be possible.

#TinyCore shows that a minimalist distro can be featureful!
tinycorelinux.net

tinycorelinux.netTiny Core Linux, Micro Core Linux, 12MB Linux GUI Desktop, Live, Frugal, ExtendableWelcome - Tiny Core Linux

📢 Do you remember the xz supply chain attack (or backdoor) that happened one year ago and nearly compromised half the world? (I think you do)

I claim that we could have automatically detected this backdoor in NixOS thanks to reproducible-builds!

-> Go read about it in my blog post: luj.fr/blog/how-nixos-could-ha

🔁 Boosts would be much appreciated!

luj.frHow NixOS and reproducible builds could have detected the xz backdoor for the benefit of all
More from Luj

BZip3

在 Hacker News 上看到 BZip3 的連結:「Bzip3: A spiritual successor to BZip2 (github.com/kspalaiologos)」。

雖然名字看起來與 bzip2 有關,但看起來是不同的人弄出來的東西,不過有些經典的演算法有留下來用,像是 Burrows-Wheeler transform。

另外值得一提的是,bzip2 是 1996 年出的 (不過 1.0 大約是 2000 年時出的),BZip3 的第一個 release 在 2022 年,這段時間也累積了不少有趣的演算法可以用。

無損壓縮中如果期望有比較的壓縮率,目前比較常用的應該是 LZMA 類的演算法 (差不多是 2001 年出現的),用的工具通常會是 X

blog.gslin.org/archives/2025/0

Gea-Suan Lin's BLOG · BZip3

Dear People attending #FOSDEM

The maintainer of #XZ is still in need of true support after they were abused by someone who tried to viciously introduce a backdoor to potentially millions of servers and computers.

They opened a Liberapay account here: liberapay.com/Larhzu.
They only receive 13,55€/week for now…

You know XZ is crucial for lots of critical systems. Please tip them generously.and boost this message!

(Discovery borrowed from @Sylvhem)

NOTE : due to the local laws, as a Finnish, Larhzu cannot accept money from Finnish people.

LiberapayLarhzu's profile - LiberapayI'm a free software hobbyist from Finland.
Replied in thread

@icaria36 No los conozco pero hoy me han pasado un episodio y he visto que se documentan muy bien y tratan el tema de la privacidad digital y controlan de software libre...

Este es sobre la casi introducción de una puerta trasera en ssh/etc de todos los #GNU #linux , el famoso escándolo #xz de hace unos años:

go.ivoox.com/rf/126982547

iVoox122. XZ - Tierra de Hackers - Podcast on iVooxListen and download Tierra de Hackers episodes for free. Un ingeniero de Microsoft descubre por casualidad una puerta trasera escondida en una librería usada por la inmensa mayoría de sistemas basados en...

Lasse Collin (the developer of xz-utils) has found out how to accept donations without breaking the Finnish money collection law:
github.com/tukaani-project/xz/

He has created an account on #LiberaPay with a restriction to not accept donations from Finns or people living in Finland:
liberapay.com/Larhzu/

With the recent attention, I'm sure plenty of people will be willing to donate a few dollars to help support you. Please enable the "Sponsor" feature on your repo : https://docs.github.com/en/spons...
GitHubEnable sponsorship on your repo · Issue #105 · tukaani-project/xzBy kaipee

I love playing around with #compression

In this case, it's all text-based data in csv and xml formats.

Size:

32,696,320 202411.tar
 4,384,020 202411.tar.bz2
 4,015,912 202411.tar.zst
 3,878,583 202411.tar.bz3
 3,730,416 202411.tar.xz

zstd was invoked using zstd --ultra -22
xz was invoked using xz -9e
bzip2 was invoked using bzip2 -9
bzip3 has no compression level options

Speed:

zstd    54.31user 0.25system 0:54.60elapsed 99%CPU
xz      53.80user 0.06system 0:53.93elapsed 99%CPU
bzip2    5.33user 0.01system 0:05.35elapsed 99%CPU
bzip3    3.98user 0.02system 0:04.01elapsed 99%CPU

Maximum memory usage (RSS):

zstd    706,312
xz      300,480
bzip3    75,996
bzip2     7,680

*RSS sampled up to ten times per second during execution of the commands in question

#bzip3 is freaking amazing, yo.

#DataCompression #bzip #bz3 #zstd #zst #zstandard #xz #lzma
#CouldaBeenABlost ;)

Been a while since I did this commute… but totally worth it for @leigh’s keynote on Protecting Canadian Democracy at 9am!!!

I’m heading to SecTor today and tomorrow, I look forward to seeing the Toronto cybersecurity community. I hope to see you at my keynote tomorrow on the xz-utils backdoor.

We’re at the Metro Toronto Convention Center, a few tickets are still available - register here:
blackhat.com/sector/2024/regis

#cybersecurity #opensource #toronto #xz-utils #sector

This documentary on #xz is awesome. They really point out the #opensource problem that people often feel alone and sometimes pressured. They also make the issue clear to people from outside of OpenSource or software. Realy recommend this to everyone. Especially if you want to show this issue to someone that is unfamiliar with the issues.
youtu.be/F7iLfuci75Y?si=NcGPXb

www.youtube.com - YouTubeAuf YouTube findest du die angesagtesten Videos und Tracks. Außerdem kannst du eigene Inhalte hochladen und mit Freunden oder gleich der ganzen Welt teilen.