Since it seems like there's been a lack - real or perceived - of simple information about the SSH compromise:
- An important system library, xz, was hacked recently by one of the maintainers of said library.
- The compromised code has been out in some form since February 24th.
- Most Linux operating systems should be updated as soon as possible; if you know you haven't updated anything since before February 24th, don't until your distro says it's safe.
- SteamOS is not affected.
- MacOS is not directly affected, but the compromised library is in Homebrew so if you use that, you should update as well.
- Windows is not affected, but Linux running in WSL can be so update that too.
If none of this is anything that means anything to you, you probably don't have anything to worry about.
Footnote: If you want to check if you have a crocked version of xz, run xz -V
at the command-line. Versions 5.6.0 and 5.6.1 are the versions with the compromise.
Add New Comment