The sophistication here is really interesting. And it all got caught because of a fairly obvious perf regression. It reminds of a quote I heard in one of those "real crime" shows: "There's a million ways to get caught for murder, and if you can think of half of them, you're a genius."
> And it all got caught because of a fairly obvious perf regression Always possible that was "parallel construction" evidence. Someone at a TLA discovered the attack by some other means, had a quiet Signal chat with a former colleague who works at MS...
The xz sshd backdoor rabbithole goes quite a bit deeper
11–20 of 310 posts
Re: The xz sshd backdoor rabbithole goes quite a bit deeper
#12The sophistication here is really interesting. And it all got caught because of a fairly obvious perf regression. It reminds of a quote I heard in one of those "real crime" shows: "There's a million ways to get caught for murder, and if you can think of half of them, you're a genius."
> And it all got caught because of a fairly obvious perf regression Always possible that was "parallel construction" evidence. Someone at a TLA discovered the attack by some other means, had a quiet Signal chat with a former colleague who works at MS...
Re: The xz sshd backdoor rabbithole goes quite a bit deeper
#13Re: The xz sshd backdoor rabbithole goes quite a bit deeper
#14I'm not saying it's amateur-ish to have bugs. I'm saying, if this was developed by a highly competent state-sponsored organization, you'd think they would have developed the actual exploit and tested it heavily behind closed doors, fixing all of the bugs and ensuring there were no suspicion-creating performance regressions before any of it was submitted into a public project. If there was no performance regression, much higher chance this never would have been discovered at all.
Re: The xz sshd backdoor rabbithole goes quite a bit deeper
#15The sophistication here is really interesting. And it all got caught because of a fairly obvious perf regression. It reminds of a quote I heard in one of those "real crime" shows: "There's a million ways to get caught for murder, and if you can think of half of them, you're a genius."
> And it all got caught because of a fairly obvious perf regression Always possible that was "parallel construction" evidence. Someone at a TLA discovered the attack by some other means, had a quiet Signal chat with a former colleague who works at MS...
Re: The xz sshd backdoor rabbithole goes quite a bit deeper
#16Re: The xz sshd backdoor rabbithole goes quite a bit deeper
#17Luckily, thanks to Elon, we’ll never know since you haven’t have a Twitter account to view the thread.
Re: The xz sshd backdoor rabbithole goes quite a bit deeper
#18Re: The xz sshd backdoor rabbithole goes quite a bit deeper
#19The sophistication here is really interesting. And it all got caught because of a fairly obvious perf regression. It reminds of a quote I heard in one of those "real crime" shows: "There's a million ways to get caught for murder, and if you can think of half of them, you're a genius."
> And it all got caught because of a fairly obvious perf regression Always possible that was "parallel construction" evidence. Someone at a TLA discovered the attack by some other means, had a quiet Signal chat with a former colleague who works at MS...
Though I guess you end up with some other questions if it's totally anonymous. But I often will do a quick look over commits of things that I upgrade (more for backwards compat questions than anything but)
Re: The xz sshd backdoor rabbithole goes quite a bit deeper
#20Edit : Check comments.
Yes, the backdoor hasn't been decompiled/reverse engineered yet. But it feels like clickbait to say : "It goes deeper"... Obviously. Nobody knows what it fully does yet. There was no assumption of knowing what it did.