Live data from Hacker News

Jia Tan "JiaT75": Added error text to warning when untaring with bsdtar (2021)

github.com

91–100 of 106 posts

Re: Jia Tan "JiaT75": Added error text to warning when untaring with bsdtar (2021)

#91
post #30

Earlier quoted context omitted.

> The user Jia Tan added exploit code to the 'xz' tool as part of a larger deal. Various discussions on this backdoor (in rough chronological order): * Backdoor in upstream xz/liblzma leading to SSH server compromise:† https://news.ycombinator.com/item?id=39865810 * What we know about the xz Utils backdoor that almost infected the world: https://news.ycombinator.com/item?id=39891607 * How the XZ Backdoor Works: https…

>XZ backdoor story – Initial analysis Here are parts 2 and 3 (weren't discussed on HN): >Part 2: Assessing the Y, and How, of the XZ Utils incident (social engineering) https://securelist.com/xz-backdoor-story-part-2-social-engin... >Part 3: XZ backdoor. Hook analysis https://securelist.com/xz-backdoor-part-3-hooking-ssh/113007...

Something tells me that somewhere deep in a millitary facility somewhere, somebody is getting court marshalled, if not downright worse (after having been found out, I mean ...)

  PS. Or some "unaffiliated" group somewhere is getting their SOF cut off ...

Re: Jia Tan "JiaT75": Added error text to warning when untaring with bsdtar (2021)

#92

Am I the only one a little concerned that no obvious attack has been found from this? It seems doubtful that a state actor is trying to use terminal escape sequences to hide an error message... The state actor wants code execution, not the ability to backspace some warning on a developers terminal. Besides, using such a vulnerability seems far too dangerous - those escape sequences would be plainly obvious in any log…

There had been code execution exploits tied to escape sequences, for example:

https://news.ycombinator.com/item?id=40428032 - Abusing url handling in iTerm2 and Hyper for code execution (2024-05-21)

Re: Jia Tan "JiaT75": Added error text to warning when untaring with bsdtar (2021)

#93
post #81

Earlier quoted context omitted.

Why do you write all your periods "." in this post (but not in others, per your comment history) as ".-"?

Hate to bother you with a reply on this, but, since you mention ... I beg to differ, I actually checked.- I'd hate it if I had been less than consistent :) PS. At least from about 2021 on ...

What I found was a bunch of occurrences '...' without a hyphen, which I assumed indicated the general trend, but on further searching I see that it is as you say. Nonetheless, if I may still ask, why?

Re: Jia Tan "JiaT75": Added error text to warning when untaring with bsdtar (2021)

#94
post #93

Earlier quoted context omitted.

Hate to bother you with a reply on this, but, since you mention ... I beg to differ, I actually checked.- I'd hate it if I had been less than consistent :) PS. At least from about 2021 on ...

What I found was a bunch of occurrences '...' without a hyphen, which I assumed indicated the general trend, but on further searching I see that it is as you say. Nonetheless, if I may still ask, why?

(I am in the end unsure about your question, but will try to answer it, if, by asking, you mean my general use of ".-"?

I nonetheless appreciate your curiosity).-

Re: Jia Tan "JiaT75": Added error text to warning when untaring with bsdtar (2021)

#95

Earlier quoted context omitted.

I'd be surprised if China has anything to do with this operation.

Who do you favor? One of the Russian Intel agencies? NSA? The Grugq?

At some point FOSS will need it's own agency, at this rate :)

  PS. The GNU GRU?

Re: Jia Tan "JiaT75": Added error text to warning when untaring with bsdtar (2021)

#96
post #93

Earlier quoted context omitted.

What I found was a bunch of occurrences '...' without a hyphen, which I assumed indicated the general trend, but on further searching I see that it is as you say. Nonetheless, if I may still ask, why?

(I am in the end unsure about your question, but will try to answer it, if, by asking, you mean my general use of ".-"? I nonetheless appreciate your curiosity).-

> … if, by asking, you mean my general use of ".-"?

Yup, that's what I mean.

Re: Jia Tan "JiaT75": Added error text to warning when untaring with bsdtar (2021)

#97
post #33

Earlier quoted context omitted.

I like the comment that started with "way too many arm chair 'researchers' in this thread" and then goes on to rudely say that the maintainers are doing a bad job because they merged in the original changes by Jia Tan. What are you sitting on, if not an arm chair? We all agree that the xz attack was of unparalleled sophistication and complexity, spread carefully over years , funded by a State. Many people were taken…

The question is still very relevant. Why are PR like this merged to begin with?

because there are hundreds of thousands of programmers who don't have the need for "better" and are willing to put up with C and shell scripts, and "small incremental changes"

Re: Jia Tan "JiaT75": Added error text to warning when untaring with bsdtar (2021)

#98
post #25

GitHub "community" is just awful. There are people trying to get real work done in that thread, but then there are all these random bystanders piling up to throw in their comments which range from useless to actively harmful and distracting. And it's not an isolated case, this happens pretty much always when some issues attracts attention on GH. Can't we respect the project and give the people there space to work, an…

People treat Github like social media

Github launched with the tag line "social code hosting" in 2008:

https://web.archive.org/web/20081216011059/https://github.co...

Which changed to "social coding" later:

https://web.archive.org/web/20110217073759/https://github.co...

"social coding" eventually moved to the page title, and disappeared from the page itself:

https://web.archive.org/web/20120202143623/https://github.co...

"Social code hosting" and "social coding" are not on the front page anymore, but they definitely kept all the social features.

Re: Jia Tan "JiaT75": Added error text to warning when untaring with bsdtar (2021)

#99
post #41
post #26

Earlier quoted context omitted.

I'm not who you asked, but sometimes the comments are more interesting (or perhaps intriguing, enticing, is a better way to put it) than the submission itself. Sometimes of those times my interest in the submission grows with reading some of the discussion, and then I'll read it. (Not to say I always do this, but I do definitely click first into comments more often than I go straight for the article - it allows a muc…

Interesting! But this sounds like an explanation why you read the comments without reading the article, not why you comment without reading, and those aren't inherently the same thing. So to clarify: do you comment on the content of the post without reading it? I'm specifically interested in why people comment on links and articles they didn't read. And for maximum clarity here, I mean commenting on the content of th…

Uh, maybe. Less likely to than just reading comments for sure.

But for example this thread is on such a tangent (and it could be a hell of a lot less) that TFA is completely irrelevant to what I would comment or how it would be received, so yes I might; almost certainly have on several occasions (over years and wouldn't-like-to-think-many comments).

Re: Jia Tan "JiaT75": Added error text to warning when untaring with bsdtar (2021)

#100
post #96

Earlier quoted context omitted.

(I am in the end unsure about your question, but will try to answer it, if, by asking, you mean my general use of ".-"? I nonetheless appreciate your curiosity).-

> … if, by asking, you mean my general use of ".-"? Yup, that's what I mean.

It is something of a mark of style - which, since you kindly ask - I inherited from my father, and I use as a sort of homage.-

PS. It has also, countless times, saved me when I "retroactively" needed to claim authorship of something I had writen, by pointing it out. Most people either don't notice or do and don't say ...

Post reply on HN