Live data from Hacker News

XZ Backdoor: Times, damned times, and scams

rheaeve.substack.com

171–180 of 193 posts

Re: XZ Backdoor: Times, damned times, and scams

#171
post #97
post #54

Earlier quoted context omitted.

Not sure why you’re downvoted. When you think of state actors, Israel comes very high (stuxnet etc), as well as the usual US/Russia/China/NK groups. Unit 8200 in the IDF especially have a very notable reputation. That’s not to say other counties don’t have capabilities (and this doesn’t look like you need the resources of a group like say the NSA or GCHQ for this particular attack - indeed it could just be a single l…

even a North Korean hacker would be plausible.

NK are one if the most prolific state actor countries. They aren't UTC+2 though.

Greece and Finland aren’t prolific. I’m sure they have the resources, many lone people would have. I don’t think they have the motives though. The US, Russia, China, NK and Israel have the motive, opportunity and track record. I wouldn’t rule out Ukraine either (and Ukraine is GMT+2)

I still think that an individual is the most likely candidate though.

Re: XZ Backdoor: Times, damned times, and scams

#172

Maybe a consideration: this isn't necessarily a nation state. It could literally just be one or more individuals trying to set up some sort of crypto heist. At this point we need some sort of new adage to the effect of "never attribute to nation states what can be attributed to crypto"

To me this is false. They usually like quick profits. Look no further than Ethereum and defi chains like Optimism,Polygon etc. It is so easy to write a malicious contract that even I with more than 12 years in the cryptocurrency space got had and lost 1k.

Re: XZ Backdoor: Times, damned times, and scams

#173

I wonder what the "Lessons Learned" look like from the other side? Are they whiteboarding the best strategy for distributing the timestamps of commits? Mandatory performance evaluations on all RCEs? Distribute the poisoned commits amongst more authors?

They will likely now optimize the code to not trigger high latency and also ensure no Valgrind will find any issues.

Re: XZ Backdoor: Times, damned times, and scams

#174
post #139

Earlier quoted context omitted.

I'm saying that changing sleep patterns and waking up earlier is a very common effect of aging. https://www.sleepfoundation.org/aging-and-sleep/why-do-older... YMMV but the idea that you can't grow in/out of sleep patterns is empirically false, and I know this from personal experience. For most of my life, I didn't need glasses for reading... until I suddenly did. Bodies change.

I knew most of the stuff in that article. If I wake up at 5am on full alert, mind racing, I read for a couple of hours and then go back to sleep when it's possible. I know that I can't function well on less than 7 hours, so I don't try. The article seems to be taking about people on the verge of entering "the facility", on their slow slide into dementia, who are making do despite not getting enough sleep. I'll get ba…

> The article seems to be taking about people on the verge of entering "the facility", on their slow slide into dementia

I don't know how in the world you got that from the article, but no.

Re: XZ Backdoor: Times, damned times, and scams

#175
post #37

> who regularly works in the early morning? Me > For a hacker, it is much more plausible to work in the afternoon and late at night c/hacker/younger person

No, stereotypes aside, hackers who code diligently tend to wrap their "actual work" schedule around their external obligations, and while the morning is generally filled with distractions like dealing with "morning people", after lunch (an on into the evening) there are generally far fewer interruptions. I can honestly get much more done with an uninterrupted four hours than I can in the entire eight office hours of…

> stereotypes aside, hackers

If we're putting stereotypes aside, wouldn't we also put aside the word "hackers"?

In the xz case, the term may be accurate, but we don't know the identity of the culprit(s) and have no empirical basis for even speculating about the work schedules of such people.

> If you're having peaceful mornings, I envy you.

Well, I don't work in an office. I work alone. Like a stereotypical "hacker".

Re: XZ Backdoor: Times, damned times, and scams

#176
post #85

Probably worth considering here - if this was a state-sponsored attack, it's entirely possible (and exactly what I would do if I was running such a program) that there is one person or department actually writing the code and list messages etc, and another person or team who sits between that department and the internet and whose entire job is to ensure that everything that comes out from the development team takes p…

Exactly. Once you assume that it’s more than “a lone wolf/single guy” many more things become possible. Including carefully curating things to appear in a location and to NOT appear to be more than one person.

Always .. however the holiday schedule thing does stand out as something that could have been missed by the orchestrators.

Re: XZ Backdoor: Times, damned times, and scams

#177

Poor Jia. Two whole years of work down the drain. If you're reading this Jia, remember that you miss 100% of the shots you don't take. Chin up, brother.

How is it down the drain? You know he didn't achieve his goals?

Occam's razor says that the perpetrators likely didn't spend years building up trust to hack some early adopters before the releases got more stable.

It would be like spending hours baking bread only to eat it before it goes in the oven.

Re: XZ Backdoor: Times, damned times, and scams

#178

Maybe a consideration: this isn't necessarily a nation state. It could literally just be one or more individuals trying to set up some sort of crypto heist. At this point we need some sort of new adage to the effect of "never attribute to nation states what can be attributed to crypto"

The attackers would have to know the distributions used by the company they are targeting, that connections are open to the internet, that the company won't change their setup over the course of several years.

Everything you are saying is so far out of the realm of possibility that it makes me wonder if you follow this stuff at all.

If you had 2+ years of spare time, and these type of skills, the attacker would be far better off just trying to get a job inside the organization they are targeting.

Re: XZ Backdoor: Times, damned times, and scams

#179

Earlier quoted context omitted.

“Trust no one! The minute God crapped out the third caveman, a conspiracy was hatched against one of them! ” - Gen. Hunter Gathers, OSI (The Venture Bros.) There are parties who have effectively endless resources and motivation to mock up a false-flag event to steer the responsibility for this a certain way. They're all very, very good at covering their tracks, and even the most experienced security researchers will…

> Never, ever install bleeding-edge software in production, for any reason. But for any X which is mainstream today someone was always the first of X. And even then being the second or third is still cutting edge. For a certain kind of company it makes sense to play this way, but if it were everyone then we'd have a tragedy.

That's why you run X in your sandbox/QA/testing/whatever-you-call-it environment, safe from the prying eyes of the public internet and the private data of users. Once it's all good there, and the community has come to a consensus about it being safe and ready-for-release, that's when you can put it wherever you want.

99.9% of releases for packages like this are boring bugfixes and stuff, not earth-shattering new features. You're not at a competitive disadvantage for not having taken this version of xz and having routed all of your traffic through it.

Re: XZ Backdoor: Times, damned times, and scams

#180
post #5

Shame on me for not reading more before my now removed comment. Shout-out for doing this level of analysis and guessing, as with everything in this incident, fascinating and tantalizing to wonder about. It is interesting, at least one of the things listed as suspicious is something I do with some frequency. I will sometimes work on what is logically three commits and not chunk them out until the very end. A bit rando…

> A bit random, but has there been speculation on why this seemed to only target rpm/deb packaging?

The payload only works on systems that connect their sshd to systemd-notify -- which is not true for many Linux distributions beyond Debian-based and RH-based anyway (e.g. Arch Linux doesn't do this).

Post reply on HN