Live data from Hacker News

XZ Backdoor: Times, damned times, and scams

rheaeve.substack.com

11–20 of 193 posts

Re: XZ Backdoor: Times, damned times, and scams

#12
post #3

One of Jia’s followers on GitHub is form Eastern Europe. Edit: it’s a meme. Apparently. I feel like an old man. > illia-git This user is suspected to be a part of an online ransomware organization. Please report any suspicious activity to GitHub security. Poland

[deleted]

Re: XZ Backdoor: Times, damned times, and scams

#16
post #14

I dont know what the XZ backdoor is about but, to assume someone putting backdoors into software would work usual working days and hours has to be very naïve. The whole premise of the article is based on a false assumption IMO.

If you’ve missed probably the largest cyber security story since stuxnet, and arguably bigger than that, I suggest you start looking at the last few days.

Start here.

https://news.ycombinator.com/item?id=39865810

Re: XZ Backdoor: Times, damned times, and scams

#18
post #5

Shame on me for not reading more before my now removed comment. Shout-out for doing this level of analysis and guessing, as with everything in this incident, fascinating and tantalizing to wonder about. It is interesting, at least one of the things listed as suspicious is something I do with some frequency. I will sometimes work on what is logically three commits and not chunk them out until the very end. A bit rando…

> A bit random, but has there been speculation on why this seemed to only target rpm/deb packaging?

I don't think much speculation is needed. RPM and deb catches every Enterprise Linux distribution, to the best of my knowledge.

rpm catches Red Hat and all derivatives like CentOS, Alma Linux etc, as well as SuSE, Amazon Linux, and even Microsoft's Mariner Linux (now renamed Azure Linux).

deb catches Debian and Ubuntu.

That's a huge global install base just through those two targets.

Re: XZ Backdoor: Times, damned times, and scams

#19
post #15

FBI could subpoena GitHub for IP addresses.

Not going to be useful if they consistently used a VPN to access GitHub. But people make mistakes sometimes.

history shows that it is generally very hard to not slip up here and there, especially if you are not expecting to be a huge target.

Re: XZ Backdoor: Times, damned times, and scams

#20
post #16
post #14

I dont know what the XZ backdoor is about but, to assume someone putting backdoors into software would work usual working days and hours has to be very naïve. The whole premise of the article is based on a false assumption IMO.

If you’ve missed probably the largest cyber security story since stuxnet, and arguably bigger than that, I suggest you start looking at the last few days. Start here. https://news.ycombinator.com/item?id=39865810

[deleted]
Post reply on HN