Live data from Hacker News

The xz sshd backdoor rabbithole goes quite a bit deeper

twitter.com

181–190 of 310 posts

Re: The xz sshd backdoor rabbithole goes quite a bit deeper

#181
post #14

The weird thing about this one is how it seems super professional in some ways, and rather amateur in others. Professional in the sense of spending a long time building up an identity that seemed trustworthy enough to be made maintainer of an important package, of probably involving multiple people in social manipulation attacks, of not leaking the true identity and source of the attack, and the sophistication and ob…

You probably have seen lots of films deificating state-sponsored organisations.

SSO are made by humans under real constrainsts in time, money, personal. It is almost impossible to make something perfect that nobody in the world could detect.

In the world there are people with different backgrounds that could use techniques that you never accounted for. Maybe is a technique used in biology to study DNA, or for counting electrons in a microscope or the background radiation in astronomy.

For example, I have seen strange people like that reverse engineer encrypted chips that were "impossible" to in a very easy way because nobody expected it. They spend 10million dollars protecting something and someone removed the protection using $10.

Re: The xz sshd backdoor rabbithole goes quite a bit deeper

#182

Earlier quoted context omitted.

We could be faced with a form of Survivorship Bias here[0]. I find that thought rather chilling. [0] https://en.wikipedia.org/wiki/Survivorship_bias

Which would mean that we have all kinds of active backdoors in our systems without us knowing it. But wouldn't they be detected at some point by someone? Or would they be silently removed again after some time so the attackers are not revealed?

Attacks on a given system or site can be expected to be removed (or auto-removed) after the operation ended, potentially w/o trace. But for supply-chain attacks there's always a history (if someone bothers to investigate).

Re: The xz sshd backdoor rabbithole goes quite a bit deeper

#183

Earlier quoted context omitted.

You probably have too high expectations when you hear the "state-sponsored" part. Every large organization will inevitably end up like any other. They also have bureaucracy, deadlines, production cycle, poor communication between teams, the recent iOS "maybe-a-backdoor" story also shows that they don't always care about burning the vulnerabilities because they amassed a huge pile of them.

state-sponsored organizations in this space could be usually military-like organizational structure that has people with dedication and motivation unlike corporate workers. command structure can mean less bureaucracy (can also mean more bureaucracy too in some ways) when it is directly aligned with their mission. national patriotism motivations mean they are more dedicated and focused than a typical corporate worker.…

[deleted]

Re: The xz sshd backdoor rabbithole goes quite a bit deeper

#184

Earlier quoted context omitted.

You probably have too high expectations when you hear the "state-sponsored" part. Every large organization will inevitably end up like any other. They also have bureaucracy, deadlines, production cycle, poor communication between teams, the recent iOS "maybe-a-backdoor" story also shows that they don't always care about burning the vulnerabilities because they amassed a huge pile of them.

state-sponsored organizations in this space could be usually military-like organizational structure that has people with dedication and motivation unlike corporate workers. command structure can mean less bureaucracy (can also mean more bureaucracy too in some ways) when it is directly aligned with their mission. national patriotism motivations mean they are more dedicated and focused than a typical corporate worker.…

I would say you put too much faith into military-like organization as well. However, from what I can tell it's usually just ordinary security researchers and devs with dubious morals (some are probably even former cybercriminals) that usually don't even have the need-to-know and aren't necessarily aware of every single aspect of their work. The entire thing is likely compartmentalized to hell.

You can't conjure quality from nothing (especially if it's pure patriotism/jingoism), large organizations are bound to work with mediocrities and dysfunctional processes, geniuses don't scale. (I feel like stating the obvious)

Re: The xz sshd backdoor rabbithole goes quite a bit deeper

#185
post #97

Earlier quoted context omitted.

The abrupt change in time-of-day when commits occurred supports the theory that Jai Tan is more than one person: https://twitter.com/birchb0y/status/1773871381890924872

The text near the box makes it sound like these are just the fixes - not adding the test files but updating them. At that point it would have been clear “the race is on” to avoid detection, so it’s not too surprising someone would work late to salvage the operation.

Whoops, you're right. So this isn't really evidence of anything.

Out of interest I looked up the other commit at that time of day visible in that graph, laying on the arrow. It's [1], which changes the git URL from git.tukaani.org to github.com. Of course, moving the project hosting to github was part of the attack.

[1] https://git.tukaani.org/?p=xz.git;a=commitdiff;h=e1b1a9d6370...

Re: The xz sshd backdoor rabbithole goes quite a bit deeper

#186
post #14

The weird thing about this one is how it seems super professional in some ways, and rather amateur in others. Professional in the sense of spending a long time building up an identity that seemed trustworthy enough to be made maintainer of an important package, of probably involving multiple people in social manipulation attacks, of not leaking the true identity and source of the attack, and the sophistication and ob…

States have spent decades if not centuries building up espionage apparatus.

All of the testing and development that goes into avoiding bugs has a tendency to run counter to the goals of secrecy or speed.

Secret, fast, well tested. Choose 2.

Re: The xz sshd backdoor rabbithole goes quite a bit deeper

#187

I haven't been following this story super closely but I find it extremely odd that I've heard zero discussion about the perpetrator of this hack.

I would be interested in semantic analysis of the communication from the involved online personas, similar to what was done for Satoshi, to point to a cultural direction. Would also be interesting to see if there were semantic style differences over time pointing to different people acting as the personas.

Since it would be quite a lot of code that has been committed as well, would also be interesting to see if code style differences could be found pointing to more people involved than only one.

Re: The xz sshd backdoor rabbithole goes quite a bit deeper

#188
post #14

The weird thing about this one is how it seems super professional in some ways, and rather amateur in others. Professional in the sense of spending a long time building up an identity that seemed trustworthy enough to be made maintainer of an important package, of probably involving multiple people in social manipulation attacks, of not leaking the true identity and source of the attack, and the sophistication and ob…

My favorite theory is that Jia Tan is a troll. They tried some silly patches and were surprised they got accepted. What started as a little joke on the side because covid made you stay at home slowly spiraled into "I wonder how far I can push this?"

Two years are enough to make yourself familiar with open ssh, ifuncs etc.

Then you do silly things like "hey um I need to replace the bad test data with newly generated data, this time using a fixed seed so that they are reproducible", but you don't actually tell anyone the seed for the new data. Then you lol when that gets past the maintainers no questions asked.

In the end they maybe just wanted to troll a coworker, like play some fart noises while they listen to music, and since they use Debian well, you better find a way to backdoor something in Debian to get into their machine.

Like back in the day when sasser sabotaged half the internet and "security experts" said they have a plausible lead to Russia – which as is turned out was because said security experts ran strings on the binary and found Russian text – put there by the German teen who wrote sasser "for teh lulz".

Re: The xz sshd backdoor rabbithole goes quite a bit deeper

#189

Earlier quoted context omitted.

I picture some division in [nation-state] where they're constantly creating personas, slowly working all sorts of languishing open source packages with few maintainers (this is the actual hard, very slow part), then once they have a bit of an in, they could recruit more technical expertise. The division is run by some evil genius who knows this could pay off big, but others are skeptical, so their resources are prett…

Moxie's reasons for disallowing Signal distribution via F-droid always rang a little flat to me ( https://github.com/signalapp/Signal-Android/issues/127 ). Lots of chatter about the supposedly superior security model of Google Play Store, and as a result fewer eyes independently building and testing the Signal code base. Everyone is entitled to their opinions, but independent and reproducible builds seem like a net p…

The link provides interesting reading, but I believe Moxie must have changed his opinion later: I have never had Google Play Store on my phone, but I could install Signal. I am pretty sure I did not install it from any dodgy site. It warned when it got outdated. Not sure how updates work, not using it anymore.

Re: The xz sshd backdoor rabbithole goes quite a bit deeper

#190
post #167

I haven't been following this story super closely but I find it extremely odd that I've heard zero discussion about the perpetrator of this hack.

> However, I believe that he is actually from somewhere in the UTC+02 (winter)/UTC+03 (DST) timezone, which includes Eastern Europe (EET), but also Israel (IST) https://rheaeve.substack.com/p/xz-backdoor-times-damned-time...

> but also Israel (IST)

I had the same thought myself initially, but the analysis suggests a work-week that includes Fri, which precludes Israel (where the work week is Sun-Thu and not Mon-Fri), as well as celebrating Christmas and New Year's which are not official holidays in Israel. It isn't uncommon for younger people to take a day off for New Year's since it is an excuse to party, or for Jews with eastern European origins to celebrate Novy God, but I don't know of any Christmas celebrations.

Obviously these could be faked, but then why fake a Mon-Fri work week and not also fake the work hours to match it? To me it seems like an unlikely hypothesis.

Post reply on HN