Replies: 3 comments
|
Well, as far as things are currently known, only the backdoored releases are problematic. The stable Linux dists usually did not already include these versions and the unstable/rolling release dists reverted to safe versions. For borg, the situation is like this:
Considering trust in liblzma in general: borg could not just remove lzma compression, because that would render all lzma compressed repos unusable. The only point in time we could do that is when migrating from borg1 to borg2 where we could recompress stuff to something non-lzma. |
|
Thanks very much for the clarification. |
|
Closing this as outdated: it has seen no activity for a long time and predates the current borg releases. If this still affects you on a current version - borg 1.4.x (stable) or the borg 2.0.0 beta - please open a new discussion with up-to-date details. |
Uh oh!
There was an error while loading. Please reload this page.
I'm guessing the answer is yes but best to check: is it still safe to use lzma compression given the recent xz Utils scare - https://arstechnica.com/security/2024/04/what-we-know-about-the-xz-utils-backdoor-that-almost-infected-the-world/
All reactions