Live data from Hacker News

The xz sshd backdoor rabbithole goes quite a bit deeper

twitter.com

1–10 of 310 posts

Re: The xz sshd backdoor rabbithole goes quite a bit deeper

#4
The sophistication here is really interesting. And it all got caught because of a fairly obvious perf regression. It reminds of a quote I heard in one of those "real crime" shows: "There's a million ways to get caught for murder, and if you can think of half of them, you're a genius."

Re: The xz sshd backdoor rabbithole goes quite a bit deeper

#6

The sophistication here is really interesting. And it all got caught because of a fairly obvious perf regression. It reminds of a quote I heard in one of those "real crime" shows: "There's a million ways to get caught for murder, and if you can think of half of them, you're a genius."

> And it all got caught because of a fairly obvious perf regression

Always possible that was "parallel construction" evidence.

Someone at a TLA discovered the attack by some other means, had a quiet Signal chat with a former colleague who works at MS...

Re: The xz sshd backdoor rabbithole goes quite a bit deeper

#7

The sophistication here is really interesting. And it all got caught because of a fairly obvious perf regression. It reminds of a quote I heard in one of those "real crime" shows: "There's a million ways to get caught for murder, and if you can think of half of them, you're a genius."

Maybe I’m just being naive or too trusting, but this is sort of what I think when folks are getting worried about other backdoors like this in the wild.

Is it that they just got unlucky to get caught, or is this type of attack just too hard to pull off in practice?

I’d like to think the later. But, we really don’t know.

Post reply on HN