Live data from Hacker News

What we know about the xz Utils backdoor that almost infected the world

arstechnica.com

171–180 of 336 posts

Re: What we know about the xz Utils backdoor that almost infected the world

#171
post #62

Earlier quoted context omitted.

To clarify (1), we should not be exchanging tarballs, period. Regardless of whether it's different from what's in the source repository. It's 2024, not 1994. If something masquerading as open-source software is not committed to, and built from, a publicly verifiable version-controlled repository, it might as well not exist.

So all of Fabrice Bellard's projects ( https://bellard.org/ ) should not exist?

Most of his well-known projects have public git repositories that you can clone, inspect, and contribute to.

Re: What we know about the xz Utils backdoor that almost infected the world

#172

Why do they say "almost" infected the world? At least 3 quite popular Linux distributions (arch, gentoo, and opensuse tumbleweed) ended up shipping the backdoor _for weeks_ , and it was most definitely working in at least tumbleweed. For weeks! A backdoored ssh! Hardly "almost".

I hope Open Source maintainers and the big companies get the message -- they need to change the financial outlook of open source maintaining.

How would it have changed anything in this specific case?

Re: What we know about the xz Utils backdoor that almost infected the world

#173

Earlier quoted context omitted.

> 8. This sucks to say, but code reviews and handing off maintainership, at the moment, need to take into account geopolitical considerations. That won't help. There's no evidence that Jia Tan is a real name, or even a real person for that matter. If projects stop accepting contributions from asian-sounding names, the next attack will just use Richard Jones as a name.

I think you could interpret this as "you need to know, personally, the party you're handing this off to, and make reasonable judgments as to whether or not they could be easily compromised by bad actors". Like, meeting someone at several dev conferences should be a requirement at the very least.

This is almost impossible for remote OSS maintainers. Do you want people to upload passports? And what if a three agency can easily produce whatever material you want?

Re: What we know about the xz Utils backdoor that almost infected the world

#174
post #62

Earlier quoted context omitted.

To clarify (1), we should not be exchanging tarballs, period. Regardless of whether it's different from what's in the source repository. It's 2024, not 1994. If something masquerading as open-source software is not committed to, and built from, a publicly verifiable version-controlled repository, it might as well not exist.

So all of Fabrice Bellard's projects ( https://bellard.org/ ) should not exist?

if these projects have any value, someone will clone them to a public repository.

Re: What we know about the xz Utils backdoor that almost infected the world

#175

Earlier quoted context omitted.

> WRT 2, no, it's not. > Trust your intuition, but you can never do that if you never meet IRL. I'm sure Edward Snowden also met up with colleagues in the office at least a few times. May have even passed a security clearance. > Also, it's not racist or xenophobic to recognize that some countries exercise nearly complete control over their citizens (and sometimes indirectly over non-citizens), and that those people c…

> I'm sure Edward Snowden also met up with colleagues in the office at least a few times. May have even passed a security clearance. And that's why we know who Edward Snowden is. That's more than we can say about Jia Tan. Say what you will about what he did and why, it is going to be very, very hard for someone to explain to a contract's security auditor why, in the year 2024, a commit from an account known to belong…

Let's use the current theory that this is a state sponsored attack. If that's the case, another Jia Tan will be recruited. The identity of a single person simply doesn't matter. All that matters is that the attack was attempted.

Consider the issue of candidates who lie in the interviewing process by hiring other people to interview on their behalf. Now replace "interview" with "attend conference". This is just adding another vector of blind trust waiting to be abused.

Re: What we know about the xz Utils backdoor that almost infected the world

#176
post #94

Earlier quoted context omitted.

I don't think that #8 implies that projects should stop accepting contributions from Asian-sounding names. To me it means that people should be more careful who they give access. It doesn't matter if it was China or some other state or organization pretended to be China, the problem is that people don't expect that open source contributor wouldn't act in altruistic way, but can be a malicious entity.

And to build on your point (hopefully), one way of understanding #8 is that it's not out of the question that bad actors have the time resource and patience to coordinate long-term campaigns of significant subtlety, the type of which is more easily pulled off by a state actor. Facts such as those should inform our presumptions about when and where people enjoy the benefit of the doubt.

For example, we hope that Linus is not a long-term agent of the Suojelupoliisi - but how would you prove it?

Ideally, the "proof is in the code" and the review setup is strong enough that it could handle a Compromised Linus™, even if it couldn't handle multiple compromises.

Re: What we know about the xz Utils backdoor that almost infected the world

#177
post #172

Earlier quoted context omitted.

I hope Open Source maintainers and the big companies get the message -- they need to change the financial outlook of open source maintaining.

How would it have changed anything in this specific case?

This might solve the original author's issues, AND might also attract other people to do the job. The more people, the more eyes. It's definitely not a silver bullet, but I would be surprised that OSS maintainers are fine with the current financial arrangement, or lack of it.

Re: What we know about the xz Utils backdoor that almost infected the world

#178

Earlier quoted context omitted.

I think you could interpret this as "you need to know, personally, the party you're handing this off to, and make reasonable judgments as to whether or not they could be easily compromised by bad actors". Like, meeting someone at several dev conferences should be a requirement at the very least.

This is almost impossible for remote OSS maintainers. Do you want people to upload passports? And what if a three agency can easily produce whatever material you want?

Sounds like it's time for someone to either pay a few visits to the remote maintainer or give them a scholarship for attending a few conferences.

Re: What we know about the xz Utils backdoor that almost infected the world

#179

Why do they say "almost" infected the world? At least 3 quite popular Linux distributions (arch, gentoo, and opensuse tumbleweed) ended up shipping the backdoor _for weeks_ , and it was most definitely working in at least tumbleweed. For weeks! A backdoored ssh! Hardly "almost".

I hope Open Source maintainers and the big companies get the message -- they need to change the financial outlook of open source maintaining.

I think the message would more likely be "don't use open source and pay for closed source" than "give money to open source and cross your fingers that it does something".

Re: What we know about the xz Utils backdoor that almost infected the world

#180

I have said this before and I'm saying it again: Open source maintainers' first responsibility is to take care of him/herself, mentally and financially. You guys should proactively seek payments from whoever uses your work commercially, and if the $$ is not good enough, you are on your own to continue do this voluntarily. If you keep the front door open, eventually thieves will come and steal your stuffs. By the same…

Next logical step in this misguided way of thinking: “do a great service to the world by subverting open source software until maintainers get their due”.

No, the ends do not justify the means.

Post reply on HN