Live data from Hacker News

What we know about the xz Utils backdoor that almost infected the world

arstechnica.com

181–190 of 336 posts

Re: What we know about the xz Utils backdoor that almost infected the world

#181

Earlier quoted context omitted.

I hope Open Source maintainers and the big companies get the message -- they need to change the financial outlook of open source maintaining.

I think the message would more likely be "don't use open source and pay for closed source" than "give money to open source and cross your fingers that it does something".

Either way, it gives more jobs and $$$ to software developers in general. I'm fine with both :)

Just imagine how many more jobs will be created if every large company decides to roll their own stuffs. A lot are actually doing this, but not enough.

Re: What we know about the xz Utils backdoor that almost infected the world

#182
post #11

I’m guessing the original maintainer of xz handed responsibilities to Jia Tan without ever seeing him/her or at least sharing a phone call. Is that common to only communicate only through email/github? I guess some maintainers of open source projects will be more cautious after this story.

What does it change? Assuming that either:

- Jia Tan was initially a trustworthy actor that subsequently became malicious (maybe they were paid or compromised somehow)

- Jia Tan was always malicious, but played the long game by starting with legitimate contributions/intent for 1-2 years

How would meeting them for real have any impact?

Re: What we know about the xz Utils backdoor that almost infected the world

#183

Earlier quoted context omitted.

I think the message would more likely be "don't use open source and pay for closed source" than "give money to open source and cross your fingers that it does something".

Either way, it gives more jobs and $$$ to software developers in general. I'm fine with both :) Just imagine how many more jobs will be created if every large company decides to roll their own stuffs. A lot are actually doing this, but not enough.

That just sounds like the broken window fallacy then. "It's good we have broken windows so the window makers have jobs".

Re: What we know about the xz Utils backdoor that almost infected the world

#184

I have said this before and I'm saying it again: Open source maintainers' first responsibility is to take care of him/herself, mentally and financially. You guys should proactively seek payments from whoever uses your work commercially, and if the $$ is not good enough, you are on your own to continue do this voluntarily. If you keep the front door open, eventually thieves will come and steal your stuffs. By the same…

Next logical step in this misguided way of thinking: “do a great service to the world by subverting open source software until maintainers get their due”. No, the ends do not justify the means.

Sometimes good ends can ONLY be brought by bad means.

Like, realistically, how would you convince the Forbes 500 to increase spending on software security? They won't budge if no one is knocking the doors.

In general, it is in human nature that we prefer to mend the situation as late as possible, as long as it is not too late, instead of curing a disease before it develops. People who do the first thing are praised and hailed, while people who do the second are laughed at.

Re: What we know about the xz Utils backdoor that almost infected the world

#185

Earlier quoted context omitted.

> I'm sure Edward Snowden also met up with colleagues in the office at least a few times. May have even passed a security clearance. And that's why we know who Edward Snowden is. That's more than we can say about Jia Tan. Say what you will about what he did and why, it is going to be very, very hard for someone to explain to a contract's security auditor why, in the year 2024, a commit from an account known to belong…

Let's use the current theory that this is a state sponsored attack. If that's the case, another Jia Tan will be recruited. The identity of a single person simply doesn't matter. All that matters is that the attack was attempted. Consider the issue of candidates who lie in the interviewing process by hiring other people to interview on their behalf. Now replace "interview" with "attend conference". This is just adding…

It raises the bar quite a bit.

Especially when you've met Jia Tan and the new Jia Tan is obviously not the same person.

Meeting in person is quite literally the opposite of blind trust. Blind trust would be assuming that the person physically sitting on the other end of the internet connection and controlling Jia Tan's keys is the same Jia Tan you had lunch with a few months ago.

Re: What we know about the xz Utils backdoor that almost infected the world

#186

This represents a massive failure of the Open Source model and it's worth thinking carefully about as more and more people advocate for fully open source AI models. People could spend a lot of time on token safety features only to have them backdoored by a sneaky PR and it's not clear what level of damage this could cause in the near future.

Isn't it the opposite, though? The whole thing was caught precisely because it was open source. Sure, you can argue that the vulnerability was introduced by a contributor, but what prevents the same thing from happening in a private repository, perpetrated by an actual employee? Especially if you consider that many vulnerabilities can be introduced with code more likely to pass as legitimate mistakes.

Re: What we know about the xz Utils backdoor that almost infected the world

#187
post #161
post #59

Earlier quoted context omitted.

> 4. Libsystemd is a problem for the ecosystem. People get dismissed as systemd haters for pointing this out but it's big, complicated, has a lot of dependencies and most programs use a tiny fraction of it. Encouraging every service to depend on it for initialization notifications is insane. I couldn't agree more. Coming from the BSD world, systemd is a shock to the system; it's monstrous and has tendrils everywhere.

If you actually come from BSD, you'd hopefully recognize a set of different utilities combined to form a holistic system released under a single name. It's not a new idea. Besides, the gpp is incorrect: systemd dependencies are not needed for initialisation notifications.

[deleted]

Re: What we know about the xz Utils backdoor that almost infected the world

#188

Earlier quoted context omitted.

Either way, it gives more jobs and $$$ to software developers in general. I'm fine with both :) Just imagine how many more jobs will be created if every large company decides to roll their own stuffs. A lot are actually doing this, but not enough.

That just sounds like the broken window fallacy then. "It's good we have broken windows so the window makers have jobs".

Since that already happened, let's drink from the half-full bottle.

Re: What we know about the xz Utils backdoor that almost infected the world

#189

Earlier quoted context omitted.

> WRT 2, no, it's not. > Trust your intuition, but you can never do that if you never meet IRL. I'm sure Edward Snowden also met up with colleagues in the office at least a few times. May have even passed a security clearance. > Also, it's not racist or xenophobic to recognize that some countries exercise nearly complete control over their citizens (and sometimes indirectly over non-citizens), and that those people c…

> I'm sure Edward Snowden also met up with colleagues in the office at least a few times. May have even passed a security clearance. And that's why we know who Edward Snowden is. That's more than we can say about Jia Tan. Say what you will about what he did and why, it is going to be very, very hard for someone to explain to a contract's security auditor why, in the year 2024, a commit from an account known to belong…

[deleted]

Re: What we know about the xz Utils backdoor that almost infected the world

#190

Earlier quoted context omitted.

This is almost impossible for remote OSS maintainers. Do you want people to upload passports? And what if a three agency can easily produce whatever material you want?

Sounds like it's time for someone to either pay a few visits to the remote maintainer or give them a scholarship for attending a few conferences.

The big companies can do that. But then there is also the question of -- how many of these critical OS libraries are there in the wilderness?
Post reply on HN