Live data from Hacker News

Several Russian developers lose kernel maintainership status

lwn.net

151–160 of 314 posts

Re: Several Russian developers lose kernel maintainership status

#151

Earlier quoted context omitted.

Yeah im sure those Chinese and NK hackers are keen to document their blackmail, no way that could go badly for them

It's open source, any exploit introduced by a maintainer is self-documenting. Provide a single example for the Linux kernel, please.

I would argue nobody needs to provide an example. IMO, we can assume an action to be taken if:

1. The mechanisms for its existence exist

2. There is motivation of a large enough scale

3. The scale of the actors is large enough

The Linux kernel is very large, and nation-states like Russia are also very large. There is a very high motivation for a backdoor to exist for the Russian government. And the mechanisms are certainly in place to create such a backdoor.

So, I conclude there would absolutely be a Russian backdoor planted, if it isn't already. For the same reasons I conclude Windows probably has multiple backdoors for US agencies.

As a side-note, the scale of the Linux Kernel matters here. It's over a billion lines of code. It's truly trivial to sneak in an exploit and have it never be discovered. You can't prove a negative here - just because we haven't seen an exploit doesn't mean they don't exist. Also, we have found MANY bugs in the Linux kernel. Are they exploits intentionally planted? Virtually impossible to tell. Some bugs have existed for decades before discovery.

You should assume your operating systems already contain many exploits. Thus, we have tools like encryption, firewalls, and trusted repos to protect us anyway.

Note this doesn't mean I support the move. Certainly, any other country could implant backdoors (and probably have already). However, the Linux kernel kind of sort of belongs to the West, and the West kind of sort of has an alliance. So it makes sense why Russia is singled out.

Re: Several Russian developers lose kernel maintainership status

#152
post #6

Earlier quoted context omitted.

Probably not sanctions, but national security concerns. The former aims to punish and worsen the situation of the other country, the latter aims to reduce the attack vector and improve the situation of the US.

If I were a KGB (FSB) agent with a task to undermine US infrastructure with my commits in Linux kernel, using my real russian name and .ru TLD would be the last thing to do.

Sure, but if I were an agency tasked with protecting US from security threats, I would begin with the lowest hanging fruit.

Yes, probably the guy who holds up the number "3" using his thumb, index, and middle finger shouldn't be allowed in the Super Secret Vault. But the dude right behind him who has "I'm Russian" tattooed on his forehead shouldn't be allowed in either, and he's a bit easier to spot.

Re: Several Russian developers lose kernel maintainership status

#153
post #142

The email thread continues. Linus later responded with: >No, but I'm not a lawyer, so I'm not going to go into the details that I - and other maintainers - were told by lawyers. >I'm also not going to start discussing legal issues with random internet people who I seriously suspect are paid actors and/or have been riled up by them. Which I find pretty concerning statements, quite a disservice to the community. It's a…

[flagged]

Re: Several Russian developers lose kernel maintainership status

#154
post #31

Strongly opposed to any sort of sanction regime that results in this.

Let me spell it out for you: If Project P in Country A is identified by Country B as a potential target for planting cyber-attack-enabling backdoors, Country B has an incentive to find people to put a backdoor in P. If Country B is a free country with rights and ethics, they will say "Help us put a backdoor in P. We'll pay you very well for services rendered," or try to get someone who already works for Country B int…

So all that an evil Russian who wants to commit murder by way of a git commit has to do is...

register a free gmail account and come up with a fake name. Gotcha. Certainly no bad guy will ever think of this.

Re: Several Russian developers lose kernel maintainership status

#155
post #78

Earlier quoted context omitted.

Do sanctions ever actually work as intended? To this casual bystander it seems like they usually hurt innocent citizens far more than the leaders of the usually authoritarion regime that it targets.

>To this casual bystander it seems like they usually hurt innocent citizens far more than the leaders of the usually authoritarion regime that it targets. That's kinda the point. The common folk put pressure on their leaders to correct their behavior.

"Here, we'll hurt you so you'll go fight the guy who claims he's the only one protecting you from us."

Has that strategy ever worked?

Re: Several Russian developers lose kernel maintainership status

#156
post #114
post #31

Earlier quoted context omitted.

Let me spell it out for you: If Project P in Country A is identified by Country B as a potential target for planting cyber-attack-enabling backdoors, Country B has an incentive to find people to put a backdoor in P. If Country B is a free country with rights and ethics, they will say "Help us put a backdoor in P. We'll pay you very well for services rendered," or try to get someone who already works for Country B int…

Removing US based kernel maintainers from positions in which they could conceivably help insert a backdoor into the kernel hopefully removes the incentive for the US government to threaten (or carry out) horrific violence against these individuals and their families. cough xz cough

It would only work if the specific government agency/actor could successfully conceal such actions from the rest of the government agencies, courts, media etc. etc. No such safety checks exist in Russia or other pseudo-fascist states.

If the Russian government is blackmailing you your are certainly screwed. In US.. well it depends but you could quite easily bring down the people doing this to you with yourself if you chose not to comply. Therefore no rational US government "actor" would engage in something like that outside of extreme circumstances.

Re: Several Russian developers lose kernel maintainership status

#157
post #72
post #69

Not a good idea for Linux to get involved in geopolitical drama. Any self-respecting maintainer will not come back after this. Linux might have a lot of developers, but has a hard time finding and retaining maintainers. This is not a good development.

It's not a geopolitical drama or melodrama, Linux Foundation needs to follow the laws of US where it's located. It's the same as any other American company

Linux Foundation was never supposed to stifle collaboration in the kernel. They are supposed to be a way to support Linux in a tax-advantaged way, full stop.

EFF should start a fork if any part of them still stands for what's in their name.

Re: Several Russian developers lose kernel maintainership status

#158
post #31

Earlier quoted context omitted.

Let me spell it out for you: If Project P in Country A is identified by Country B as a potential target for planting cyber-attack-enabling backdoors, Country B has an incentive to find people to put a backdoor in P. If Country B is a free country with rights and ethics, they will say "Help us put a backdoor in P. We'll pay you very well for services rendered," or try to get someone who already works for Country B int…

[flagged]

The Russian government could compel pretty much anyone in Russia to do anything with minimal actual cost to it.

Governments in US and other democratic states would be risking a lot more if if other government agencies, courts, media etc. figure that out. Therefore as long as they are somewhat rational they are less likely to engage in something like that.

Re: Several Russian developers lose kernel maintainership status

#159
post #78

Strongly opposed to any sort of sanction regime that results in this.

Do sanctions ever actually work as intended? To this casual bystander it seems like they usually hurt innocent citizens far more than the leaders of the usually authoritarion regime that it targets.

> innocent citizens

Do you not think that at least 50% of all people in Russia would vote for Putin or his affiliates (even if the elections weren't falsified)? Therefore most people in Russia are certainly not innocent.

Re: Several Russian developers lose kernel maintainership status

#160

Earlier quoted context omitted.

>To this casual bystander it seems like they usually hurt innocent citizens far more than the leaders of the usually authoritarion regime that it targets. That's kinda the point. The common folk put pressure on their leaders to correct their behavior.

"Here, we'll hurt you so you'll go fight the guy who claims he's the only one protecting you from us." Has that strategy ever worked?

South Africa? Rhodesia?

But sure.. usually it doesn't really work out.

Of course weakening the target country economically, politically and militarily is still better than nothing,

Post reply on HN