Live data from Hacker News

Reflections on Distrusting xz

joeyh.name

201–210 of 335 posts

Re: Reflections on Distrusting xz

#201

> It feels good to not need to worry about dpkg and tar. I only plan to maintain this fork minimally, eg security fixes. This is exactly the problem in the first place, lack of support for maintainers. OP themselves say "I will only minimally maintain this fork". Okay, but it's so easy in hindsight to criticize what has happened. > Hopefully Lasse Collin will consider these possibilities and address them in his respo…

> I can't even imagine how he's feeling these days.

None of this is his problem or fault. I see no reason he should feel anything about this. Keeping everyone safe was never his job. He wrote code and gave it away for free. That should be enough.

Re: Reflections on Distrusting xz

#202
post #8

One thing that comes to mind is that “Jia Tan” might be more accurately seen as a “sleeper” of some sort: a foot soldier who infiltrates a juicy open source project and waits for further instructions; backdooring sshd might not have been part of the original plan. Which raises the concerning question of how much more sleeper maintainers there are.

>Which raises the concerning question of how much more sleeper maintainers there are. Given how easy the infiltration is and how extremely hard to detect it is, likely a lot. For an intelligence operation it is also extremely cheap, you just need a few knowledgeable developers spending some time each week on the project. The upside being a backdoor into a significant portion of infrastructure, the downside being wast…

> Given how easy the infiltration is and how extremely hard to detect it is, likely a lot.

I read it exactly the other way around: the infiltration took years and detecting it was the default with a fuzzer, which had to be disabled for the exploit to succeed.

It speaks to the hardening and that hardening should be required more. And of course the precarious roles of maintainers, which have been discussed elsewhere.

Re: Reflections on Distrusting xz

#203
post #170

The US spends $30-60 billion a year on agriculture and subisides [1]. This is controversial for all the obvious reasons. Without subsidies we'd waste less food but overproduction of food is an intentional objective of these programs. Why? Because if there's a major drought or crops are lost to ice or snow or flooding, Americans won't starve. It's why we have things like the US government having a reserve of over a bi…

It's not valid to regard the potential of negative consequences in any sphere of human life as a "national security risk".

It's not valid to presume that the only way to mitigate risks is through top-down political intervention.

And it's absolutely not valid to presume that making FOSS communities dependent on political subsidies would not have much worse and much longer term consequences than the problems we are trying to mitigate.

In fact, it's entirely possible that the political intermediaries who control the purse-strings would have an even greater capacity to introduce their own backdoors or otherwise compromise security in pursuit of their own ambitions.

What you're proposing here might well represent trying to keep out one set of threat actors by handing the keys to the castle over to another set of threat actors. And this would be on top all of the other problems it would cause: convergence toward homogeneous monocultures, project priorities being distorted by political incentives, vested interests using political influence to suppress competition from FOSS projects, etc.

It's worth pointing out that the swift detection and remediation of the xz backdoor by the community almost immediately after the threat actor pulled the trigger on their two-year long con represents a resounding success of the FOSS "many eyes" model, and it's not clear what politicians throwing money around would add to the equation.

Re: Reflections on Distrusting xz

#204

> It feels good to not need to worry about dpkg and tar. I only plan to maintain this fork minimally, eg security fixes. This is exactly the problem in the first place, lack of support for maintainers. OP themselves say "I will only minimally maintain this fork". Okay, but it's so easy in hindsight to criticize what has happened. > Hopefully Lasse Collin will consider these possibilities and address them in his respo…

> I can't even imagine how he's feeling these days. None of this is his problem or fault. I see no reason he should feel anything about this. Keeping everyone safe was never his job. He wrote code and gave it away for free. That should be enough.

> I see no reason he should feel anything about this.

Absolutely agree, but from the sounds of the emails at least, he was going through a bad time then, and nobody feels good when they realise they were taken advantage of.

Re: Reflections on Distrusting xz

#205

Earlier quoted context omitted.

I think at this point is clear that everybody has to assume that XZ is completely rotten and can no longer be trusted. Is it XZ easy to replace with some other compression tool? Or has it been so widely adopted that is going to take huge effort moving out of it?

There is no reason to assume that. Even if you assume every commit since Jia became a maintainer is malicious, the version from 3 years ago is perfectly fine. Zstd has a number of benefits over Xz that may warrant its use as a replacement of the latter, and this will likely be a motivating factor to do so. But calling it entirely rotten is going way too far IMO

What keeps ringing in my head is the "." that was found that invalidates compilation. I personally don't buy it (but is my opinion).

Re: Reflections on Distrusting xz

#206
post #170

The US spends $30-60 billion a year on agriculture and subisides [1]. This is controversial for all the obvious reasons. Without subsidies we'd waste less food but overproduction of food is an intentional objective of these programs. Why? Because if there's a major drought or crops are lost to ice or snow or flooding, Americans won't starve. It's why we have things like the US government having a reserve of over a bi…

It seems very stupid to me. How long will it be before the government starts pressuring these maintainers to do the things the government wants?

For example, introducing their own backdoors.

Re: Reflections on Distrusting xz

#207

Earlier quoted context omitted.

He never mentioned about any financial problems, it was more about his mental health

And would mental health issues have kept him from working on xz if that had been part of his day job?

I’ve been in similar burnout situations, and the difference between work and side projects did not matter to my mental health. The money was not an issue, it was headspace and fatigue.

Re: Reflections on Distrusting xz

#208

> It feels good to not need to worry about dpkg and tar. I only plan to maintain this fork minimally, eg security fixes. This is exactly the problem in the first place, lack of support for maintainers. OP themselves say "I will only minimally maintain this fork". Okay, but it's so easy in hindsight to criticize what has happened. > Hopefully Lasse Collin will consider these possibilities and address them in his respo…

> I can't even imagine how he's feeling these days. None of this is his problem or fault. I see no reason he should feel anything about this. Keeping everyone safe was never his job. He wrote code and gave it away for free. That should be enough.

anyone who has ever been pickpocketed or robbed or worse will know reason and feelings are different things

Re: Reflections on Distrusting xz

#209
post #36

Earlier quoted context omitted.

I once got a (probably scam) offer for adding a cryptominer to a library that I maintained at that time. And a more serious offer to add trackers to a popular >1M installs app. Both cases I obviously ignored it. But it made me aware of a nasty attack vector: someone who's thanklessly building a wordpress-plugin, pip, npm, or whatever software, thanklessly dealing with issues, PRs, support, maintainence, often for no…

I believe the problem of thankless maintenance is best solved with two things: the thanks (yes, we are all human and want recognition and appreciation from fellow humans)[0], and a stable employment (work for a good large business while open-sourcing what’s possible)[1]. If you do OSS for profit, then it can become a question of where is more money; but if you work a reliable job with insurance, relationships and oth…

> and a stable employment (work for a good large business while open-sourcing what’s possible)

Even if it was hypothetically possible to open-source basically everything that the team in which I work produces:

The software that I work on is very specialized software that is used by the company's employees and customers for specialized purposes. Imagine some nice LoB application that is actually somewhat comfortable to use. It basically does "what the users need" and is thus deeply ingrained in some parts of the company's workflows. The only use someone outside the industry might have for it is "cosplaying being employed in this industry".

A lot of software that is developed (in particular in companies that don't sell or rent software) is of this kind.

Thus: the open-source scene does in my opinion not have any use for a huge amount of software that is actually developed and actively used.

Post reply on HN