Earlier quoted context omitted.
To clarify (1), we should not be exchanging tarballs, period. Regardless of whether it's different from what's in the source repository. It's 2024, not 1994. If something masquerading as open-source software is not committed to, and built from, a publicly verifiable version-controlled repository, it might as well not exist.
So all of Fabrice Bellard's projects ( https://bellard.org/ ) should not exist?
What we know about the xz Utils backdoor that almost infected the world
171–180 of 336 posts
Re: What we know about the xz Utils backdoor that almost infected the world
#172Why do they say "almost" infected the world? At least 3 quite popular Linux distributions (arch, gentoo, and opensuse tumbleweed) ended up shipping the backdoor _for weeks_ , and it was most definitely working in at least tumbleweed. For weeks! A backdoored ssh! Hardly "almost".
I hope Open Source maintainers and the big companies get the message -- they need to change the financial outlook of open source maintaining.
Re: What we know about the xz Utils backdoor that almost infected the world
#173Earlier quoted context omitted.
> 8. This sucks to say, but code reviews and handing off maintainership, at the moment, need to take into account geopolitical considerations. That won't help. There's no evidence that Jia Tan is a real name, or even a real person for that matter. If projects stop accepting contributions from asian-sounding names, the next attack will just use Richard Jones as a name.
I think you could interpret this as "you need to know, personally, the party you're handing this off to, and make reasonable judgments as to whether or not they could be easily compromised by bad actors". Like, meeting someone at several dev conferences should be a requirement at the very least.
Re: What we know about the xz Utils backdoor that almost infected the world
#174Earlier quoted context omitted.
To clarify (1), we should not be exchanging tarballs, period. Regardless of whether it's different from what's in the source repository. It's 2024, not 1994. If something masquerading as open-source software is not committed to, and built from, a publicly verifiable version-controlled repository, it might as well not exist.
So all of Fabrice Bellard's projects ( https://bellard.org/ ) should not exist?
Re: What we know about the xz Utils backdoor that almost infected the world
#175Earlier quoted context omitted.
> WRT 2, no, it's not. > Trust your intuition, but you can never do that if you never meet IRL. I'm sure Edward Snowden also met up with colleagues in the office at least a few times. May have even passed a security clearance. > Also, it's not racist or xenophobic to recognize that some countries exercise nearly complete control over their citizens (and sometimes indirectly over non-citizens), and that those people c…
> I'm sure Edward Snowden also met up with colleagues in the office at least a few times. May have even passed a security clearance. And that's why we know who Edward Snowden is. That's more than we can say about Jia Tan. Say what you will about what he did and why, it is going to be very, very hard for someone to explain to a contract's security auditor why, in the year 2024, a commit from an account known to belong…
Consider the issue of candidates who lie in the interviewing process by hiring other people to interview on their behalf. Now replace "interview" with "attend conference". This is just adding another vector of blind trust waiting to be abused.
Re: What we know about the xz Utils backdoor that almost infected the world
#176Earlier quoted context omitted.
I don't think that #8 implies that projects should stop accepting contributions from Asian-sounding names. To me it means that people should be more careful who they give access. It doesn't matter if it was China or some other state or organization pretended to be China, the problem is that people don't expect that open source contributor wouldn't act in altruistic way, but can be a malicious entity.
And to build on your point (hopefully), one way of understanding #8 is that it's not out of the question that bad actors have the time resource and patience to coordinate long-term campaigns of significant subtlety, the type of which is more easily pulled off by a state actor. Facts such as those should inform our presumptions about when and where people enjoy the benefit of the doubt.
Ideally, the "proof is in the code" and the review setup is strong enough that it could handle a Compromised Linus™, even if it couldn't handle multiple compromises.
Re: What we know about the xz Utils backdoor that almost infected the world
#177Earlier quoted context omitted.
I hope Open Source maintainers and the big companies get the message -- they need to change the financial outlook of open source maintaining.
How would it have changed anything in this specific case?
Re: What we know about the xz Utils backdoor that almost infected the world
#178Earlier quoted context omitted.
I think you could interpret this as "you need to know, personally, the party you're handing this off to, and make reasonable judgments as to whether or not they could be easily compromised by bad actors". Like, meeting someone at several dev conferences should be a requirement at the very least.
This is almost impossible for remote OSS maintainers. Do you want people to upload passports? And what if a three agency can easily produce whatever material you want?
Re: What we know about the xz Utils backdoor that almost infected the world
#179Why do they say "almost" infected the world? At least 3 quite popular Linux distributions (arch, gentoo, and opensuse tumbleweed) ended up shipping the backdoor _for weeks_ , and it was most definitely working in at least tumbleweed. For weeks! A backdoored ssh! Hardly "almost".
I hope Open Source maintainers and the big companies get the message -- they need to change the financial outlook of open source maintaining.
Re: What we know about the xz Utils backdoor that almost infected the world
#180I have said this before and I'm saying it again: Open source maintainers' first responsibility is to take care of him/herself, mentally and financially. You guys should proactively seek payments from whoever uses your work commercially, and if the $$ is not good enough, you are on your own to continue do this voluntarily. If you keep the front door open, eventually thieves will come and steal your stuffs. By the same…
No, the ends do not justify the means.