Live data from Hacker News

Who rooted kernel.org servers two years ago?

arstechnica.com

31–40 of 50 posts

Re: Who rooted kernel.org servers two years ago?

#31

Weird parallel between the NSA revelations and the Global Warming movement, every odd weather event is attributed to global warming, every odd security event it attributed to the NSA. That said, as I recall the "hack" was a lot less impressive than it seemed (some folks in Google's Linux team were administrators of kernel.org). I do wonder about the lack of a definitive online after action report though. Seems someon…

Could you stop lying about Climate Science please?

I think that he (she?) was comparing some extra-alarmists' (Al Gore-type) tendencies to attribute every abnormal weather pattern to global warming. We should all agree that crying wolf weakens legitimate claims about climate change and ocean acidification.

Re: Who rooted kernel.org servers two years ago?

#32

A feature of civilian security is that "It was restored from Git" is doesn't immediately spark a concern that Git could be compromised. I'm not saying that it is, but compromising Git is certainly the sort of thing which would occur to a state sponsored espionage agency. And if one were seeking to compromise the Linux toolchain, it would certainly be a very attractive link. So attractive that not including it in a mu…

Version control systems are a bad target. They are too simple , too deterministic, and too networked. You can steal their data, but if you insert something, you will get caught. Yeah, there are exceptions, all of them proprietrary. There is no reason to trust GIT less just because some companies can make even version control hard.

Even assuming that Git is unassailable with a billion dollar budget:

How long has the Linux kernel been under development?

How long has it been version controlled using Git?

How long has it been a potential target of state sponsored espionage agencies?

The potential adversaries have been taking cryptography and security seriously since long before the Linux community. They have larger budgets and significant expertise backed by patriotism and economic rewards.

Compared to pulling a nuclear submarine wreck from the depths of the Pacific, Git might not appear so difficult.

Re: Who rooted kernel.org servers two years ago?

#33

Earlier quoted context omitted.

What are the ramifications if this is what happened? I strongly suspect they were able to get a copy of the kernel source code... They could be doing anything with it.. Porting it to a new platform.. Compiling it with unsafe GCC flags.. Or worse..

This reminds me of a friend's response to the idea that the TouchID in the new iphone could be a way for the NSA to get your fingerprints: "Just imagine the shitstorm if they put a camera in there. Or a microphone."

There's no good way yet to uniquely identify a person based on a (dodgy) picture of them or sample of their voice. Whereas fingerprints are used for this daily* and a quickly searchable database of these (or just their "hashes") would be incredibly useful to _somebody_.

*I'm not raising the issue of whether they _should_ be or not here, just that they are.

Re: Who rooted kernel.org servers two years ago?

#34

Until there is a post-mortem, we have to assume the simplest explanation: gross facepalm, like leaving something 777 open to the world.

That's the pre-911 world you're living in, no seriously, a derp is the best case, careful people plan for scenarios other than the best-case failure.

I have enough respect for the kernel maintainers to assume that they would be able to muster the courage to confess to derping up their file permissions in a time span less than two years.

Re: Who rooted kernel.org servers two years ago?

#36

Weird parallel between the NSA revelations and the Global Warming movement, every odd weather event is attributed to global warming, every odd security event it attributed to the NSA. That said, as I recall the "hack" was a lot less impressive than it seemed (some folks in Google's Linux team were administrators of kernel.org). I do wonder about the lack of a definitive online after action report though. Seems someon…

That's not a weird parallel, it's confirmation bias. There are both AGW sceptics and AGW believers who draw broad conclusions from localised data when it suits their view. It's a very normal human foible.

Re: Who rooted kernel.org servers two years ago?

#37

A feature of civilian security is that "It was restored from Git" is doesn't immediately spark a concern that Git could be compromised. I'm not saying that it is, but compromising Git is certainly the sort of thing which would occur to a state sponsored espionage agency. And if one were seeking to compromise the Linux toolchain, it would certainly be a very attractive link. So attractive that not including it in a mu…

Version control systems are a bad target. They are too simple , too deterministic, and too networked. You can steal their data, but if you insert something, you will get caught. Yeah, there are exceptions, all of them proprietrary. There is no reason to trust GIT less just because some companies can make even version control hard.

>> but if you insert something, you will get caught

Is there a tool for checking that?

Re: Who rooted kernel.org servers two years ago?

#38
post #2

So let's speculate about what the article almost-but-doesn't-quite propose: The NSA, or related parties, was responsible for the breach. There was an investigation and postmortem, but because of an NSL or other gag-type order, they couldn't accurately publish what they discovered. So they figured that not releasing a report was better than releasing a report that either intentionally misled or pretended not to have f…

It's not a big leap. The report hasn't been disclosed because they are under legal obligation not to disclose. The report hasn't been disclosed because they are corrupt. The report hasn't been disclosed because they are embarrassed. The report hasn't been disclosed because they are lazy. The report hasn't been disclosed because they are incompetent. What other possibilities exist? Which one is most likely?

[deleted]

Re: Who rooted kernel.org servers two years ago?

#39
post #2

So let's speculate about what the article almost-but-doesn't-quite propose: The NSA, or related parties, was responsible for the breach. There was an investigation and postmortem, but because of an NSL or other gag-type order, they couldn't accurately publish what they discovered. So they figured that not releasing a report was better than releasing a report that either intentionally misled or pretended not to have f…

You're so far off :)

Re: Who rooted kernel.org servers two years ago?

#40
post #9
post #2

So let's speculate about what the article almost-but-doesn't-quite propose: The NSA, or related parties, was responsible for the breach. There was an investigation and postmortem, but because of an NSL or other gag-type order, they couldn't accurately publish what they discovered. So they figured that not releasing a report was better than releasing a report that either intentionally misled or pretended not to have f…

> WELCOME TO THE CRAPTOPOCLYPSE: From now on, every security discussion wastes 15 minutes on “but did the NSA DO IT?!?!’ no matter how absurd. https://twitter.com/grahamvsworld/status/375793987992715264 I'd be more curious to see the actual report before speculating.

Let's just agree that from now on the NSA is responsible for all future security and privacy problems. If proven otherwise, we will assume the NSA is willing to share the blame. Then we can move forward with the rest of the discussion.
Post reply on HN