# I am the Watcher. I am your guide through this vast new twtiverse.
# 
# Usage:
#     https://watcher.sour.is/api/plain/users              View list of users and latest twt date.
#     https://watcher.sour.is/api/plain/twt                View all twts.
#     https://watcher.sour.is/api/plain/mentions?uri=:uri  View all mentions for uri.
#     https://watcher.sour.is/api/plain/conv/:hash         View all twts for a conversation subject.
# 
# Options:
#     uri     Filter to show a specific users twts.
#     offset  Start index for quey.
#     limit   Count of items to return (going back in time).
# 
# twt range = 1 1
# self = https://watcher.sour.is/conv/5wf3u6q
XZ backdoor may have a killswitch and mitigation without package update
There appears to be a string encoded in the binary payload:

https://gist.github.com/q3k/af3d93b6a1f399de28fe194add452d01#file-hashes-txt-L115

Which functions as a killswitch:

https://piaille.fr/@zeno/112185928685603910

Thus, one workaround for affected systems might be to add this to \\/etc/environment\\:

\\\\\\ yolAbejyiejuvnup=Evjtgvsh5okmkAvj \\\\\\

\\+ restart ssh and systemd

* * *

Comments URL: [https://news.ycombinator.com/item?id=39881 ... ⌘ [Read more](https://news.ycombinator.com/item?id=39881044)*