Live data from Hacker News

Jia Tan "JiaT75": Added error text to warning when untaring with bsdtar (2021)

github.com

1–10 of 106 posts

Re: Jia Tan "JiaT75": Added error text to warning when untaring with bsdtar (2021)

#2
I guess for those not sure of the context: The user Jia Tan added exploit code to the 'xz' tool as part of a larger deal. Wikipedia has a page on it here [1].

In this post, they are discussing some changes to print code specifically for the libarchive project, and some notable personalities in the security community chime in, including Colin Percival (Tarsnap among others) and Taviso (Google project zero among others).

[1] https://en.wikipedia.org/wiki/XZ_Utils_backdoor

Re: Jia Tan "JiaT75": Added error text to warning when untaring with bsdtar (2021)

#5
post #2

I guess for those not sure of the context: The user Jia Tan added exploit code to the 'xz' tool as part of a larger deal. Wikipedia has a page on it here [1]. In this post, they are discussing some changes to print code specifically for the libarchive project, and some notable personalities in the security community chime in, including Colin Percival (Tarsnap among others) and Taviso (Google project zero among others…

> The user Jia Tan added exploit code to the 'xz' tool as part of a larger deal.

Various discussions on this backdoor (in rough chronological order):

* Backdoor in upstream xz/liblzma leading to SSH server compromise:† https://news.ycombinator.com/item?id=39865810

* What we know about the xz Utils backdoor that almost infected the world: https://news.ycombinator.com/item?id=39891607

* How the XZ Backdoor Works: https://news.ycombinator.com/item?id=39911311

* The xz sshd backdoor rabbithole goes quite a bit deeper: https://news.ycombinator.com/item?id=39956455

* XZ backdoor story – Initial analysis: https://news.ycombinator.com/item?id=40017310

† Original report, AFAICT.

Re: Jia Tan "JiaT75": Added error text to warning when untaring with bsdtar (2021)

#10
post #4

I'm a little unclear as to why JiaT75's github account still exists? Surely this should be nuked from orbit so that no one accidentally ends up using their shady code?

removing their account doesnt remove their commits.
Post reply on HN