Live data from Hacker News

Who rooted kernel.org servers two years ago?

arstechnica.com

11–20 of 50 posts

Re: Who rooted kernel.org servers two years ago?

#11
post #4

OFF-TOPIC why is that when I hit back in Ars it creates about 10 pages in my history (didn't click anything in the page itself) this is an UX nightmare and the 3-4 articles I've looked in the past week made me cringe when trying to leave the page.

Do you have an extension blocking ads? I found the same problem and disabling the extension, stopped the problem occurring.

Re: Who rooted kernel.org servers two years ago?

#12
post #2

So let's speculate about what the article almost-but-doesn't-quite propose: The NSA, or related parties, was responsible for the breach. There was an investigation and postmortem, but because of an NSL or other gag-type order, they couldn't accurately publish what they discovered. So they figured that not releasing a report was better than releasing a report that either intentionally misled or pretended not to have f…

What are the ramifications if this is what happened? I strongly suspect they were able to get a copy of the kernel source code... They could be doing anything with it.. Porting it to a new platform.. Compiling it with unsafe GCC flags.. Or worse..

This reminds me of a friend's response to the idea that the TouchID in the new iphone could be a way for the NSA to get your fingerprints: "Just imagine the shitstorm if they put a camera in there. Or a microphone."

Re: Who rooted kernel.org servers two years ago?

#13
post #2

So let's speculate about what the article almost-but-doesn't-quite propose: The NSA, or related parties, was responsible for the breach. There was an investigation and postmortem, but because of an NSL or other gag-type order, they couldn't accurately publish what they discovered. So they figured that not releasing a report was better than releasing a report that either intentionally misled or pretended not to have f…

What are the ramifications if this is what happened? I strongly suspect they were able to get a copy of the kernel source code... They could be doing anything with it.. Porting it to a new platform.. Compiling it with unsafe GCC flags.. Or worse..

[deleted]

Re: Who rooted kernel.org servers two years ago?

#14
post #2

So let's speculate about what the article almost-but-doesn't-quite propose: The NSA, or related parties, was responsible for the breach. There was an investigation and postmortem, but because of an NSL or other gag-type order, they couldn't accurately publish what they discovered. So they figured that not releasing a report was better than releasing a report that either intentionally misled or pretended not to have f…

What are the ramifications if this is what happened? I strongly suspect they were able to get a copy of the kernel source code... They could be doing anything with it.. Porting it to a new platform.. Compiling it with unsafe GCC flags.. Or worse..

There was a discussion about this recently saying that it was highly unlikely. All the source was in Git and every git commit references the previous commit, making it highly challenging to modify an old commit without also modifying the commit id. More details: http://archive.is/Khq7R

Re: Who rooted kernel.org servers two years ago?

#15
post #14

Earlier quoted context omitted.

What are the ramifications if this is what happened? I strongly suspect they were able to get a copy of the kernel source code... They could be doing anything with it.. Porting it to a new platform.. Compiling it with unsafe GCC flags.. Or worse..

There was a discussion about this recently saying that it was highly unlikely. All the source was in Git and every git commit references the previous commit, making it highly challenging to modify an old commit without also modifying the commit id. More details: http://archive.is/Khq7R

Yes, it's unlikely they modified the source in git.. But it's possible they were able to download a copy and modify it locally... Possibly adding comments to document certain blocks of code.. Or adding unofficial patches for zfs support... Or worse..

Re: Who rooted kernel.org servers two years ago?

#16
post #14

Earlier quoted context omitted.

What are the ramifications if this is what happened? I strongly suspect they were able to get a copy of the kernel source code... They could be doing anything with it.. Porting it to a new platform.. Compiling it with unsafe GCC flags.. Or worse..

There was a discussion about this recently saying that it was highly unlikely. All the source was in Git and every git commit references the previous commit, making it highly challenging to modify an old commit without also modifying the commit id. More details: http://archive.is/Khq7R

whoosh :)

Re: Who rooted kernel.org servers two years ago?

#17
post #14

Earlier quoted context omitted.

What are the ramifications if this is what happened? I strongly suspect they were able to get a copy of the kernel source code... They could be doing anything with it.. Porting it to a new platform.. Compiling it with unsafe GCC flags.. Or worse..

There was a discussion about this recently saying that it was highly unlikely. All the source was in Git and every git commit references the previous commit, making it highly challenging to modify an old commit without also modifying the commit id. More details: http://archive.is/Khq7R

[deleted]

Re: Who rooted kernel.org servers two years ago?

#18
post #6

Promises on important matters are made every day and subsequently broken. Any reason why Ars is bringing this up now?

Because this was a high profile breach and in light of the recent NSA revelations the reader is expected to connect the dots. Just my take on it.

Re: Who rooted kernel.org servers two years ago?

#19

Until there is a post-mortem, we have to assume the simplest explanation: gross facepalm, like leaving something 777 open to the world.

Possible. But even then it would be good to know as much as possible on who actually broke in and what they did.

Re: Who rooted kernel.org servers two years ago?

#20

Earlier quoted context omitted.

What are the ramifications if this is what happened? I strongly suspect they were able to get a copy of the kernel source code... They could be doing anything with it.. Porting it to a new platform.. Compiling it with unsafe GCC flags.. Or worse..

This reminds me of a friend's response to the idea that the TouchID in the new iphone could be a way for the NSA to get your fingerprints: "Just imagine the shitstorm if they put a camera in there. Or a microphone."

Or a GPS.
Post reply on HN