Live data from Hacker News

Who rooted kernel.org servers two years ago?

arstechnica.com

1–10 of 50 posts

Re: Who rooted kernel.org servers two years ago?

#2
So let's speculate about what the article almost-but-doesn't-quite propose:

The NSA, or related parties, was responsible for the breach. There was an investigation and postmortem, but because of an NSL or other gag-type order, they couldn't accurately publish what they discovered. So they figured that not releasing a report was better than releasing a report that either intentionally misled or pretended not to have figured out what happened.

I know, this is a pretty big leap. But regardless -- what does it mean? What are the ramifications if this is what happened?

Re: Who rooted kernel.org servers two years ago?

#3
It's a shame this article doesn't have anything new to add, although I'm glad someone is reminding the world we still don't know what happened. Before the Snowden revelations this summer I'd assume it was a simple drive-by, incompetence. Now it's hard to see this as anything other than a deliberate attack by an Advanced Persistent Threat.

Re: Who rooted kernel.org servers two years ago?

#4
OFF-TOPIC why is that when I hit back in Ars it creates about 10 pages in my history (didn't click anything in the page itself) this is an UX nightmare and the 3-4 articles I've looked in the past week made me cringe when trying to leave the page.

Re: Who rooted kernel.org servers two years ago?

#7
post #2

So let's speculate about what the article almost-but-doesn't-quite propose: The NSA, or related parties, was responsible for the breach. There was an investigation and postmortem, but because of an NSL or other gag-type order, they couldn't accurately publish what they discovered. So they figured that not releasing a report was better than releasing a report that either intentionally misled or pretended not to have f…

What are the ramifications if this is what happened?

I strongly suspect they were able to get a copy of the kernel source code... They could be doing anything with it.. Porting it to a new platform.. Compiling it with unsafe GCC flags.. Or worse..

Re: Who rooted kernel.org servers two years ago?

#8
post #4

OFF-TOPIC why is that when I hit back in Ars it creates about 10 pages in my history (didn't click anything in the page itself) this is an UX nightmare and the 3-4 articles I've looked in the past week made me cringe when trying to leave the page.

Are you using Chrome? I believe this is a known bug. I just hit back repeatedly until I'm free to go.

Re: Who rooted kernel.org servers two years ago?

#9
post #2

So let's speculate about what the article almost-but-doesn't-quite propose: The NSA, or related parties, was responsible for the breach. There was an investigation and postmortem, but because of an NSL or other gag-type order, they couldn't accurately publish what they discovered. So they figured that not releasing a report was better than releasing a report that either intentionally misled or pretended not to have f…

> WELCOME TO THE CRAPTOPOCLYPSE: From now on, every security discussion wastes 15 minutes on “but did the NSA DO IT?!?!’ no matter how absurd.

https://twitter.com/grahamvsworld/status/375793987992715264

I'd be more curious to see the actual report before speculating.

Re: Who rooted kernel.org servers two years ago?

#10
post #2

So let's speculate about what the article almost-but-doesn't-quite propose: The NSA, or related parties, was responsible for the breach. There was an investigation and postmortem, but because of an NSL or other gag-type order, they couldn't accurately publish what they discovered. So they figured that not releasing a report was better than releasing a report that either intentionally misled or pretended not to have f…

If that were the case why would gregkh say that "There will be a report later this year".
Post reply on HN