Live data from Hacker News

The xz sshd backdoor rabbithole goes quite a bit deeper

twitter.com

11–20 of 310 posts

Re: The xz sshd backdoor rabbithole goes quite a bit deeper

#11
post #6

The sophistication here is really interesting. And it all got caught because of a fairly obvious perf regression. It reminds of a quote I heard in one of those "real crime" shows: "There's a million ways to get caught for murder, and if you can think of half of them, you're a genius."

> And it all got caught because of a fairly obvious perf regression Always possible that was "parallel construction" evidence. Someone at a TLA discovered the attack by some other means, had a quiet Signal chat with a former colleague who works at MS...

Interesting possibilty but it seems like the "discovery" story is too complex and unbelievable.

Re: The xz sshd backdoor rabbithole goes quite a bit deeper

#12
post #6

The sophistication here is really interesting. And it all got caught because of a fairly obvious perf regression. It reminds of a quote I heard in one of those "real crime" shows: "There's a million ways to get caught for murder, and if you can think of half of them, you're a genius."

> And it all got caught because of a fairly obvious perf regression Always possible that was "parallel construction" evidence. Someone at a TLA discovered the attack by some other means, had a quiet Signal chat with a former colleague who works at MS...

There doesn’t seem to be any evidence to support this whatsoever yet it’s nearly impossible to disprove. Classic conspiracy theory.

Re: The xz sshd backdoor rabbithole goes quite a bit deeper

#13
post #5
post #2

Luckily, thanks to Elon, we’ll never know since you haven’t have a Twitter account to view the thread.

Change "twitter" to "twiiit" to get a random nitter instance: https://twiiit.com/bl4sty/status/1776691497506623562

No thanks, I support an open web.

Re: The xz sshd backdoor rabbithole goes quite a bit deeper

#14
The weird thing about this one is how it seems super professional in some ways, and rather amateur in others. Professional in the sense of spending a long time building up an identity that seemed trustworthy enough to be made maintainer of an important package, of probably involving multiple people in social manipulation attacks, of not leaking the true identity and source of the attack, and the sophistication and obfuscation techniques used. Yet also a bit amateur-ish in the bugs and performance regressions that slipped out into production versions.

I'm not saying it's amateur-ish to have bugs. I'm saying, if this was developed by a highly competent state-sponsored organization, you'd think they would have developed the actual exploit and tested it heavily behind closed doors, fixing all of the bugs and ensuring there were no suspicion-creating performance regressions before any of it was submitted into a public project. If there was no performance regression, much higher chance this never would have been discovered at all.

Re: The xz sshd backdoor rabbithole goes quite a bit deeper

#15
post #6

The sophistication here is really interesting. And it all got caught because of a fairly obvious perf regression. It reminds of a quote I heard in one of those "real crime" shows: "There's a million ways to get caught for murder, and if you can think of half of them, you're a genius."

> And it all got caught because of a fairly obvious perf regression Always possible that was "parallel construction" evidence. Someone at a TLA discovered the attack by some other means, had a quiet Signal chat with a former colleague who works at MS...

It seems like a much more suitable parallel construction story to invent in this instance would be something like "there were valgrind issues reported, but I couldn't reproduce them, so I sanity checked the tarball was the same as the git source. It wasn't."

Re: The xz sshd backdoor rabbithole goes quite a bit deeper

#18
post #5

Earlier quoted context omitted.

Change "twitter" to "twiiit" to get a random nitter instance: https://twiiit.com/bl4sty/status/1776691497506623562

No thanks, I support an open web.

You support the open web by stealing from the closed one!

Re: The xz sshd backdoor rabbithole goes quite a bit deeper

#19
post #6

The sophistication here is really interesting. And it all got caught because of a fairly obvious perf regression. It reminds of a quote I heard in one of those "real crime" shows: "There's a million ways to get caught for murder, and if you can think of half of them, you're a genius."

> And it all got caught because of a fairly obvious perf regression Always possible that was "parallel construction" evidence. Someone at a TLA discovered the attack by some other means, had a quiet Signal chat with a former colleague who works at MS...

Wouldn't it have been easier to just have someone drive-by comment on the changes in the source tree in the comment? Like "what's up with this?"

Though I guess you end up with some other questions if it's totally anonymous. But I often will do a quick look over commits of things that I upgrade (more for backwards compat questions than anything but)

Re: The xz sshd backdoor rabbithole goes quite a bit deeper

#20
Without having a Twitter account I have a really hard time following these threads. Is there some write up?

Edit : Check comments.

Yes, the backdoor hasn't been decompiled/reverse engineered yet. But it feels like clickbait to say : "It goes deeper"... Obviously. Nobody knows what it fully does yet. There was no assumption of knowing what it did.

Post reply on HN