Live data from Hacker News

The xz backdoor thing reminds me of a story

rigor-mortis.nmrc.org

51–60 of 99 posts

Re: The xz backdoor thing reminds me of a story

#51
post #9

Earlier quoted context omitted.

You don't have to give your employer a bank account number, but they still have to pay you. Quite unusual for a tech contractor though.

> You don't have to give your employer a bank account number As a Norwegian that sounds so alien. They couldn't do anything but deposit money, so why wouldn't you?

In America they can and do also take money out of your account, to correct errors supposedly, but sometimes also in error. I still get paid on paper to this day because to me the terms of the direct deposit agreement are overbroad.

Re: The xz backdoor thing reminds me of a story

#55

Earlier quoted context omitted.

I don't understand this. You go through all this trouble to build a fake identity and then you don't do this one simple thing to make sure you look like a real employee?

Banks have a stricter KYC than companies that hire someone. The person would have needed to forge an identity that stood up to the scrutiny of the bank or risk linking it to their real identity or something. If they aren't doing it for the pay check seems like a bunch of extra work for not much gain.

Bingo.

Leaving the checks uncashed means there's less of a paper trail to follow.

Re: The xz backdoor thing reminds me of a story

#56
post #5

I remember a few months ago there was a discussion[1] here about how fossil, the VCS for sqlite, should bring in a dependency on mermaid charts already. Nothing against mermaid, but I guess supply chain attacks are hard to conceptualise until they happen. When we're shortsighted we risk our mitigations against vague but serious threat models losing out against convenience. [1] https://news.ycombinator.com/item?id=388…

Could a plugin architecture accommodate this?

Many moons ago, I was active on the fossil list (right before it became a forum, one of the many things fossil has built-in), hoping to achieve the opposite of this: a libfossil containing the core technology for a fossil repo, without all the other stuff that comes along with it.

Someone had started work on this, but was unable to complete it. The maintainers were willing to consider the idea, but not do it themselves, which is (always, for any request, on any open source project, at any time) completely understandable.

I still think it would be great if someone with the ability/interest/time made it happen. Version control is useful for many things other than software, and fossil's architecture is well-suited for a linkable all-purpose revision control library.

Re: The xz backdoor thing reminds me of a story

#57
post #9

Earlier quoted context omitted.

You don't have to give your employer a bank account number, but they still have to pay you. Quite unusual for a tech contractor though.

> You don't have to give your employer a bank account number As a Norwegian that sounds so alien. They couldn't do anything but deposit money, so why wouldn't you?

In the US, I'm fairly sure your bank account number (routing and account) can be used to withdraw money.

Re: The xz backdoor thing reminds me of a story

#58
post #45

Earlier quoted context omitted.

I'm a tech contractor. I prefer payment by check from my clients. Most can't or don't want to set up direct deposit for a part time contractor. Amounts are too large for Zelle, and I don't want to pay the fees for paypal or credit card processing if I can avoid it. My clients usually issue paper checks online. Their bank prints the check and mails it. My receiving address is my bank, which deposits checks for me when…

Maybe I'm a bit to naive since I don't know the US banking system, but at least in the EU you just need to tell someone your IBAN and Name and they can transfer money to your account. Is it that much harder in the US?

[deleted]

Re: The xz backdoor thing reminds me of a story

#59
post #31

Earlier quoted context omitted.

Pretty common in the US back then. Direct deposit is (still) only required to be provided at the company's bank, though I doubt anyone implements that minimum any more. Back in the 90s when I worked for Atari (Back in the terrible Warner period) you could only get DD at the company's bank, which was a small bank with one branch, in Sunnyvale (surely the company had another bank or two as well?). I was told they did t…

It must be bad if you are using your employees as a short term LOC. An inverse payday loan.

Using money you owe for something else for as long as you get away with is hardly alien in business in general. It is why most companies (almost every company?) delay payment of invoices for as long as legally possible, no point losing that fraction of whatever in interest (or interest saved on debt). Heck, with regard to cheques it is why banks held on to 3+ clearing periods on those and other payments for as long as they did. Doing the same with outgoings to employees isn't a stretch that would surprise me in the slightest.

Re: The xz backdoor thing reminds me of a story

#60
post #50

Earlier quoted context omitted.

> You don't have to give your employer a bank account number As a Norwegian that sounds so alien. They couldn't do anything but deposit money, so why wouldn't you?

At least in Canada, the numbers provided for direct deposit are the same numbers used for direct/pre-authorized debit (i.e. withdrawals). So, while your employer likely wouldn’t abuse that information? People may be wary of giving out those numbers unless absolutely necessary, since someone could indeed drain their bank account. They’re also the same numbers that appear on cheques, so someone could easily forge a che…

> the numbers provided for direct deposit are the same numbers used for direct/pre-authorized debit (i.e. withdrawals)

Reading up on that, it seems similar in nature to our AvtaleGiro[1]. While indeed having my account number would allow a business to issue a AvtaleGiro request, it's just a request. I would then have to go to my (online) bank and approve it, including setting up a monthly withdrawal limit. So it can't happen without action on my part.

> They’re also the same numbers that appear on cheques, so someone could easily forge a cheque in your name with those numbers.

Cheques I don't know about because they were going the way of the Dodo even when I was young, but we did have BrevGiro[2] which was a way to transfer money. However it relied on the bank sending me serialized pre-filled forms, so someone would have to steal one of those as well to be able to withdraw money from my account.

[1]: https://no.wikipedia.org/wiki/AvtaleGiro

[2]: https://no.wikipedia.org/wiki/Brevgiro

Post reply on HN