Earlier quoted context omitted.
I'm not sure why people keep misidentifying the problem as "lack of funding". Lasse Collin was doing fine as a maintainer up until Jia Tan showed up. He was psy-op'd into believing there was a crowd of angry people eagerly awaiting a new release when there wasn't. No real person was unhappy with the way he'd been maintaining xz.
Funding aside, single individuals being responsible for software is not a good thing, see bus factor.
Reflections on Distrusting xz
271–280 of 335 posts
Re: Reflections on Distrusting xz
#272Earlier quoted context omitted.
What keeps ringing in my head is the "." that was found that invalidates compilation. I personally don't buy it (but is my opinion).
What do you mean "don't buy it"?
Re: Reflections on Distrusting xz
#273Re: Reflections on Distrusting xz
#274Earlier quoted context omitted.
Arch Linux has replaced it with zstd in 2020 already. It's doable for the next major release of Debian.
Certainly, but we need an xz decompressor to read the current debian repo versions for the next decades, when they are oldstable or archived.
Re: Reflections on Distrusting xz
#275Earlier quoted context omitted.
My assumption is that this was state sponsored mass surveillance campaign of some kind but God knows what exactly they were looking for. I think if backdoor was discovered 2 or 3 months later, we maybe could understand better what they wanted to do. My speculation is that they wanted to build a massive botnet and then snoop on machines' processes and traffic looking for something. It's hard to speculate because lucki…
I find it intriguing that out of all the speculative comment threads I've read so far, none of them have suggested it was Microsoft attempting to make FOSS look bad/vulnerable.
Re: Reflections on Distrusting xz
#276To me, this is very suspicious.
Re: Reflections on Distrusting xz
#277Earlier quoted context omitted.
That one amuses me because of a character in a (iirc) fantasy book that swore all the time but used just -ing everywhere. Sadly I don’t remember what character of which book…
It's Mr Tulip, of Terry Pratchett's The Truth .
Re: Reflections on Distrusting xz
#278Earlier quoted context omitted.
I find it intriguing that out of all the speculative comment threads I've read so far, none of them have suggested it was Microsoft attempting to make FOSS look bad/vulnerable.
How would that benefit Microsoft, who owns GitHub, the home of OSS? It's not a secret that oss is vulnerable, the opportunity for MS is to sell the solution to a captive audience.
Re: Reflections on Distrusting xz
#279Earlier quoted context omitted.
>Which raises the concerning question of how much more sleeper maintainers there are. Given how easy the infiltration is and how extremely hard to detect it is, likely a lot. For an intelligence operation it is also extremely cheap, you just need a few knowledgeable developers spending some time each week on the project. The upside being a backdoor into a significant portion of infrastructure, the downside being wast…
> Given how easy the infiltration is and how extremely hard to detect it is, likely a lot. I read it exactly the other way around: the infiltration took years and detecting it was the default with a fuzzer, which had to be disabled for the exploit to succeed. It speaks to the hardening and that hardening should be required more. And of course the precarious roles of maintainers, which have been discussed elsewhere.
You have to assume if this was an intelligence agency they didn’t burn their only agent like this.
Re: Reflections on Distrusting xz
#280Earlier quoted context omitted.
>Which raises the concerning question of how much more sleeper maintainers there are. Given how easy the infiltration is and how extremely hard to detect it is, likely a lot. For an intelligence operation it is also extremely cheap, you just need a few knowledgeable developers spending some time each week on the project. The upside being a backdoor into a significant portion of infrastructure, the downside being wast…
> Given how easy the infiltration is and how extremely hard to detect it is, likely a lot. This particular case seems to be an example of the exact opposite. It took "Jia Tan" two years to conduct all of the social engineering necessary to get into a position to introduce the backdoor, then upon doing so, was caught almost immediately, with the initial discovery not even coming from a dedicated security researcher, b…
For a nation state actor two years is nothing. Likely the entire attack didn't cost more than a couple of thousand hours of developer time. I would guess it was easily cheaper than 100k in financial terms, that is extremely efficient for an intelligence operation with the upside being access to a large amount of servers.
The method by which he got caught also depended largely upon random chance, some major "if's" needed to happen, the performance reduction was an unfortunate side effect from the perspective of the attacker, really a minor mistake exposed him. Even if he were exposed a couple months later the damage would have been enormous, if that version had become a stable part of any major distro for the next few years hundreds of thousands of machines would have been vulnerable.
There is absolutely no reason to assume that if another attack of this quality happens it will not find it's way into some stable distro.