Earlier quoted context omitted.
> You don't have to give your employer a bank account number As a Norwegian that sounds so alien. They couldn't do anything but deposit money, so why wouldn't you?
Sorry, what does being Norwegian have to do with it? Going to the physical bank with a physical check seems like too many steps no matter what country you're from.
The xz backdoor thing reminds me of a story
61–70 of 99 posts
Re: The xz backdoor thing reminds me of a story
#62Earlier quoted context omitted.
> You don't have to give your employer a bank account number As a Norwegian that sounds so alien. They couldn't do anything but deposit money, so why wouldn't you?
Because you’re trying to plant backdoors you don’t want any paper trail? Almost everyone does direct deposit. But it’s not a legal requirement for an employee to be paid that way.
Good point, good point...
I went to check, and it seems we've just recently plugged[1] that hole here in Norway. Salary and other benefits must be paid to a bank account now.
[1]: https://www.gpokonomi.no/2022/01/26/forbud-mot-kontant-utbet...
Re: The xz backdoor thing reminds me of a story
#63Earlier quoted context omitted.
Intelligence agencies can presumably mint valid SSNs along with other identity documents to use in situations like this.
They can’t forge a chipped passport unless they somehow got hold of the private key for the country’s CSCA certificate.
But seriously, why would they not be able to? They will almost certainly have high-level connections into the State Dept. (or whatever agency issues passports for your country) that allows them to create any passports they need. Same way the Police can get license plates for undercover vehicles from the DMV that don't list "One Police Plaza" if someone (i.e. "other" Police) runs the plates.
Re: The xz backdoor thing reminds me of a story
#64Earlier quoted context omitted.
Why would you need to? Passports are not required to hire a person; most americans don’t even have one.
Nor citizens of many other countries; passports are mainly for out-of-country travel purposes.
Not saying this helps in any way for employment purposes today, but the technology is out there in many places.
Re: The xz backdoor thing reminds me of a story
#65I remember a few months ago there was a discussion[1] here about how fossil, the VCS for sqlite, should bring in a dependency on mermaid charts already. Nothing against mermaid, but I guess supply chain attacks are hard to conceptualise until they happen. When we're shortsighted we risk our mitigations against vague but serious threat models losing out against convenience. [1] https://news.ycombinator.com/item?id=388…
The problem is that the people who act on this and minimise dependencies are at a significant economic disadvantage to those who don't. A project with high risk tolerance has to write a fraction of the code and solve a fraction of the problems as someone who carefully writes secure software.
The trade off isn't just "convenience", we're talking massive differentials in productivity that favour insecure models. It is much cheaper to accept that data will leak sooner or later, to the point where we can assume that if something is economically developed that is evidence it can't possibly be secure. That isn't an argument for more security though; if possible it is better to just design systems where leaks don't matter (eg, here in HN it isn't clear why I'd care about a leak - everything is already public except for the IP address in the server log).
Re: The xz backdoor thing reminds me of a story
#66Earlier quoted context omitted.
Why go through the risk of trying to deposit a cheque when the plan worked perfectly fine as is? Once you get banks involved, seems like more of a risk of something getting flagged there rather than someone in payroll noticing cheques weren't deposited within the time you were there.
People with fake identities because they're working as a spy have real bank accounts. But more importantly, cheque-cashing places give a god-awful return but would still look more legitimate then just not ever cashing anything. In short: the details of this story make no sense for the implied narrative (spy). They make a lot of sense for "not mentally well person" or "guy who suddenly had to disappear for other reaso…
I don't disagree that it was poor opsec, but the rest of the story makes it clear enough that they were burning the identity/employee quickly enough that it really didn't matter.
Re: The xz backdoor thing reminds me of a story
#67Re: The xz backdoor thing reminds me of a story
#68[flagged]
Requiring JS to read a simple article is undoubtedly wasteful, of course, but there are far worse insults you can make to you readership.
Re: The xz backdoor thing reminds me of a story
#69Earlier quoted context omitted.
Because you’re trying to plant backdoors you don’t want any paper trail? Almost everyone does direct deposit. But it’s not a legal requirement for an employee to be paid that way.
> Because you’re trying to plant backdoors you don’t want any paper trail? Good point, good point... I went to check, and it seems we've just recently plugged[1] that hole here in Norway. Salary and other benefits must be paid to a bank account now. [1]: https://www.gpokonomi.no/2022/01/26/forbud-mot-kontant-utbet...
Re: The xz backdoor thing reminds me of a story
#70Earlier quoted context omitted.
Intelligence agencies can presumably mint valid SSNs along with other identity documents to use in situations like this.
They can’t forge a chipped passport unless they somehow got hold of the private key for the country’s CSCA certificate.