XZ Backdoor: Times, damned times, and scams
rheaeve.substack.com
XZ Backdoor: Times, damned times, and scams
1–10 of 193 posts
Re: XZ Backdoor: Times, damned times, and scams
#2Re: XZ Backdoor: Times, damned times, and scams
#3Edit: it’s a meme. Apparently. I feel like an old man.
> illia-git This user is suspected to be a part of an online ransomware organization. Please report any suspicious activity to GitHub security. Poland
Re: XZ Backdoor: Times, damned times, and scams
#4Re: XZ Backdoor: Times, damned times, and scams
#5It is interesting, at least one of the things listed as suspicious is something I do with some frequency. I will sometimes work on what is logically three commits and not chunk them out until the very end.
A bit random, but has there been speculation on why this seemed to only target rpm/deb packaging?
Re: XZ Backdoor: Times, damned times, and scams
#6FBI could subpoena GitHub for IP addresses.
Re: XZ Backdoor: Times, damned times, and scams
#7Re: XZ Backdoor: Times, damned times, and scams
#8FBI could subpoena GitHub for IP addresses.
Jia Tan probably used a vpn though - we know that they did for accessing IRC (source: https://boehs.org/node/everything-i-know-about-the-xz-backdo...)
Re: XZ Backdoor: Times, damned times, and scams
#9FBI could subpoena GitHub for IP addresses.
Considering what the account was up to I sincerely doubt it was being used without Tor or a VPN.
It’s quite plausible that they didn’t manage perfect vpn usage every single time.
Re: XZ Backdoor: Times, damned times, and scams
#10One of Jia’s followers on GitHub is form Eastern Europe. Edit: it’s a meme. Apparently. I feel like an old man. > illia-git This user is suspected to be a part of an online ransomware organization. Please report any suspicious activity to GitHub security. Poland
https://knowyourmeme.com/memes/discord-user-is-a-suspected-t...