Live data from Hacker News

Who rooted kernel.org servers two years ago?

arstechnica.com

21–30 of 50 posts

Re: Who rooted kernel.org servers two years ago?

#21
post #14

Earlier quoted context omitted.

There was a discussion about this recently saying that it was highly unlikely. All the source was in Git and every git commit references the previous commit, making it highly challenging to modify an old commit without also modifying the commit id. More details: http://archive.is/Khq7R

Yes, it's unlikely they modified the source in git.. But it's possible they were able to download a copy and modify it locally... Possibly adding comments to document certain blocks of code.. Or adding unofficial patches for zfs support... Or worse..

Isn't that against the Geneva Convention?

Re: Who rooted kernel.org servers two years ago?

#22
From the 2011 kernel summit, "The attack turns out to have been part of a widespread credential-stealing network that has been operating for some years now; it is clear that the site had been owned by this network for some time before it was discovered. What also seems to be clear is that this was not a targeted attack; kernel.org was just another on a long list of broken machines."

- Jon Corbet reporting on a talk by H. Peter Anvin, https://lwn.net/Articles/464233/

Re: Who rooted kernel.org servers two years ago?

#23
post #9
post #2

So let's speculate about what the article almost-but-doesn't-quite propose: The NSA, or related parties, was responsible for the breach. There was an investigation and postmortem, but because of an NSL or other gag-type order, they couldn't accurately publish what they discovered. So they figured that not releasing a report was better than releasing a report that either intentionally misled or pretended not to have f…

> WELCOME TO THE CRAPTOPOCLYPSE: From now on, every security discussion wastes 15 minutes on “but did the NSA DO IT?!?!’ no matter how absurd. https://twitter.com/grahamvsworld/status/375793987992715264 I'd be more curious to see the actual report before speculating.

I think the point was, why hasn't the report been released yet, 2 years later?

Could be they're lazy. Could be they're embarrassed. Could be they're legally prohibited from reporting it -- which in turn could be due to a NSL.

Lots of "could be". But not entirely crazy to list all the possibilities... while waiting for the report, which we can probably all agree ought to be released by now.

Re: Who rooted kernel.org servers two years ago?

#24
A feature of civilian security is that "It was restored from Git" is doesn't immediately spark a concern that Git could be compromised.

I'm not saying that it is, but compromising Git is certainly the sort of thing which would occur to a state sponsored espionage agency. And if one were seeking to compromise the Linux toolchain, it would certainly be a very attractive link. So attractive that not including it in a multi-vector attack might be considered grossly unprofessional.

Re: Who rooted kernel.org servers two years ago?

#25
post #9

Earlier quoted context omitted.

> WELCOME TO THE CRAPTOPOCLYPSE: From now on, every security discussion wastes 15 minutes on “but did the NSA DO IT?!?!’ no matter how absurd. https://twitter.com/grahamvsworld/status/375793987992715264 I'd be more curious to see the actual report before speculating.

I think the point was, why hasn't the report been released yet, 2 years later? Could be they're lazy. Could be they're embarrassed. Could be they're legally prohibited from reporting it -- which in turn could be due to a NSL. Lots of "could be". But not entirely crazy to list all the possibilities... while waiting for the report, which we can probably all agree ought to be released by now.

My bet is on "lazy", but I think it's much easier to buy into the NSL explanation than the embarrassement one.

Re: Who rooted kernel.org servers two years ago?

#26

A feature of civilian security is that "It was restored from Git" is doesn't immediately spark a concern that Git could be compromised. I'm not saying that it is, but compromising Git is certainly the sort of thing which would occur to a state sponsored espionage agency. And if one were seeking to compromise the Linux toolchain, it would certainly be a very attractive link. So attractive that not including it in a mu…

Version control systems are a bad target. They are too simple, too deterministic, and too networked. You can steal their data, but if you insert something, you will get caught.

Yeah, there are exceptions, all of them proprietrary. There is no reason to trust GIT less just because some companies can make even version control hard.

Re: Who rooted kernel.org servers two years ago?

#27
Weird parallel between the NSA revelations and the Global Warming movement, every odd weather event is attributed to global warming, every odd security event it attributed to the NSA.

That said, as I recall the "hack" was a lot less impressive than it seemed (some folks in Google's Linux team were administrators of kernel.org). I do wonder about the lack of a definitive online after action report though. Seems someone dropped the ball on that one.

Re: Who rooted kernel.org servers two years ago?

#28

Weird parallel between the NSA revelations and the Global Warming movement, every odd weather event is attributed to global warming, every odd security event it attributed to the NSA. That said, as I recall the "hack" was a lot less impressive than it seemed (some folks in Google's Linux team were administrators of kernel.org). I do wonder about the lack of a definitive online after action report though. Seems someon…

Could you stop lying about Climate Science please?

Re: Who rooted kernel.org servers two years ago?

#29
post #2

So let's speculate about what the article almost-but-doesn't-quite propose: The NSA, or related parties, was responsible for the breach. There was an investigation and postmortem, but because of an NSL or other gag-type order, they couldn't accurately publish what they discovered. So they figured that not releasing a report was better than releasing a report that either intentionally misled or pretended not to have f…

It's not a big leap.

The report hasn't been disclosed because they are under legal obligation not to disclose.

The report hasn't been disclosed because they are corrupt.

The report hasn't been disclosed because they are embarrassed.

The report hasn't been disclosed because they are lazy.

The report hasn't been disclosed because they are incompetent.

What other possibilities exist? Which one is most likely?

Re: Who rooted kernel.org servers two years ago?

#30

Earlier quoted context omitted.

I think the point was, why hasn't the report been released yet, 2 years later? Could be they're lazy. Could be they're embarrassed. Could be they're legally prohibited from reporting it -- which in turn could be due to a NSL. Lots of "could be". But not entirely crazy to list all the possibilities... while waiting for the report, which we can probably all agree ought to be released by now.

My bet is on "lazy", but I think it's much easier to buy into the NSL explanation than the embarrassement one.

At this point, I think you basically HAVE to assume it was NSA involvement. Most of the people who were considered paranoid before seem to have been underestimating things based on what we now know.
Post reply on HN