luj.fr
research·October 1, 2025·1 min read

20251001T000000==public--how-nixos-could-have-detected-xz-attack__research

Abstract

In March 2024, a backdoor was discovered in xz, a compression software widely used across Linux distributions. This work analyzes the backdoor's mechanics and explores how bitwise build reproducibility, systematically applied within the nixpkgs bootstrap, could have mechanically detected the compromise. It proposes a concrete verification scheme based on rebuilding suspect packages after the bootstrap from independently-sourced tarballs and checking for bitwise convergence.

See also