Live data from Hacker News

Backdoor in upstream xz/liblzma leading to SSH server compromise

openwall.com

321–330 of 1001 posts

Re: Backdoor in upstream xz/liblzma leading to SSH server compromise

#321
post #146

Yikes! Do you have any info on the individual's background or possible motivations?

There is zero web presence for this person and associated email address. Looks more likely a fake identity than compromised account.

I've never had a web presencse for my associated emails due to wanting to avoid spammers. I don't have a false identity.

Re: Backdoor in upstream xz/liblzma leading to SSH server compromise

#322

Quite ironic: The most recent commit in the git repo is "Simplify SECURITY.md", committed by the same Github account which added the backdoor. https://github.com/tukaani-project/xz/commit/af071ef7702debe...

It's not ironic, this change is really sinister IMO. They want you to waste more time after you've submitted the security report and maximize the amount of back and forth. Basically the hope is that they'd be able to pester you with requests for more info/details in order to "resolve the issue" which would give them more time to exploit their targets.

Re: Backdoor in upstream xz/liblzma leading to SSH server compromise

#323

Everybody here In jumping into the pure malice bandwagon, I have a better hypothesis. Abandonment and inaction, the actual developers of these tools are elsewhere, oblivious to this drama, trying to make living because most of the time you are not compensated nor any corporation cares about making things sustainable at all. This is the default status of everything your fancy cloud depends on underneath. An attacker t…

Except that doesn't match reality. Someone has worked on xz for several years. Are you saying that this somewhat active contributor was likely actively contributing, then all of a sudden stopped, also stopped paying attention, and also allowed their account to be compromised or otherwise handed it over to a nefarious party? That fails the sniff test.

See, people drop dead from OSS projects pretty frecuently, usually because they take on other life responsabilities and there is no cushion or guard against a bus factor. Then it is very easy to get credentials compromised or have your project took over by someone else.

Re: Backdoor in upstream xz/liblzma leading to SSH server compromise

#324

Earlier quoted context omitted.

Every single commit this person ever did should immediately be rolled back in all projects.

It's weird and disturbing that this isn't the default perspective.

Imagine someone tried to revert all the commits you ever did. Doesn't sound easy.

Re: Backdoor in upstream xz/liblzma leading to SSH server compromise

#325

Earlier quoted context omitted.

Every single commit this person ever did should immediately be rolled back in all projects.

It's weird and disturbing that this isn't the default perspective.

Some of those commits might fix genuine vulnerabilities. So you might trade a new backdoor for an old vulnerability that thousands of criminal orgs have bots for exploiting.

Damage wise, most orgs aren't going to be hurt much by NSA or the Chinese equivalent getting access, but a Nigerian criminal gang? They're far more likely to encrypt all your files and demand a ransom.

Re: Backdoor in upstream xz/liblzma leading to SSH server compromise

#327
post #266
post #224

Funny how Lasse Collin started to ccing himself and Jia Tan from 2024-03-20 (that was a day of tons of xz kernel patches), he never did that before. :) https://lore.kernel.org/lkml/20240320183846.19475-2-lasse.co...

Also interesting, to me, how the GMail account for the backdoor contributor ONLY appears in the context of "XZ" discussions. Google their email address. Suggests a kind of focus, to me, and a lack of reality / genuineness.

This also means that Google might know who they are, unless they were careful to hide behind VPN or other such means.

Re: Backdoor in upstream xz/liblzma leading to SSH server compromise

#328

Jai Tan's commit history on his github profile suggests he took off for Christmas, new years, and spring break. I smell an American.

Interesting. Is there also a pattern in the times of day? (I don't so much mean the times in commits done by the developer because they can be fake. I'd be more interested in authentic times recorded by GitHub, if any such times are publicly accessible.)

Another thing would be to examine everything ever written by the user for linguistic clues. This might point towards particular native languages or a particular variant of English or towards there being several different authors.

Re: Backdoor in upstream xz/liblzma leading to SSH server compromise

#329
post #224

Funny how Lasse Collin started to ccing himself and Jia Tan from 2024-03-20 (that was a day of tons of xz kernel patches), he never did that before. :) https://lore.kernel.org/lkml/20240320183846.19475-2-lasse.co...

This is extremely suspicious.

It looks like someone may have noticed a unmaintained or lightly maintained project related to various things, and moved to take control of it.

Otherwhere in the discussion here someone mentions the domain details changed; if you have control of the domain you have control of all emails associated with it.

Re: Backdoor in upstream xz/liblzma leading to SSH server compromise

#330
post #67

The discussion to upload it to Debian is interesting on its own https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1067708

Wow, that's a lot of anonymous accounts adding comments there urging for a fast merge! And this "Hans Jansen" guy is apparently running around salsa.debian.org pushing for more updates in other projects as well: https://salsa.debian.org/users/hjansen/activity

>that's a lot of anonymous accounts

Just FYI, krygorin4545@proton.me (the latest message before the upload) was created Tue Mar 26 18:30:02 UTC 2024, about an hour earlier than the message was posted.

Proton generates PGP key upon creating the account, with the real datetime of the key (but the key does not include the timezone).

Post reply on HN