this post was submitted on 11 Mar 2025
157 points (93.9% liked)

Technology

65819 readers
5133 users here now

This is a most excellent place for technology news and articles.


Our Rules


  1. Follow the lemmy.world rules.
  2. Only tech related content.
  3. Be excellent to each other!
  4. Mod approved content bots can post up to 10 articles per day.
  5. Threads asking for personal tech support may be deleted.
  6. Politics threads may be removed.
  7. No memes allowed as posts, OK to post as comments.
  8. Only approved bots from the list below, this includes using AI responses and summaries. To ask if your bot can be added please contact a mod.
  9. Check for duplicates before posting, duplicates may be removed
  10. Accounts 7 days and younger will have their posts automatically removed.

Approved Bots


founded 2 years ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
[โ€“] palordrolap@fedia.io 5 points 19 hours ago (1 children)

local administrator privileges

... are used by distro update mechanisms and very few people turn those off, even if they don't use elevated privileges for anything else.

Admittedly, it's unlikely that a distro's repository will end up with a compromised microcode package, but it's not impossible (Remember the 7zip debacle?). And if it happens, you can be sure that whoever designs the payload will use the temporary access to install something ugly that has more permanent access.

But as you say, AMD have issued a fix. And that'd be why.

[โ€“] Rin@lemm.ee 2 points 8 hours ago

7z? You mean xz??