Live data from Hacker News

XZ Backdoor: Times, damned times, and scams

rheaeve.substack.com

21–30 of 193 posts

Re: XZ Backdoor: Times, damned times, and scams

#21
post #9
post #6

Earlier quoted context omitted.

Considering what the account was up to I sincerely doubt it was being used without Tor or a VPN.

This article asserts some opsec failures - time zones switching when they shouldn’t etc. It’s quite plausible that they didn’t manage perfect vpn usage every single time.

I'm surprised they didn't set up guards to prevent mistakes like commits with the "wrong" timezones...

Re: XZ Backdoor: Times, damned times, and scams

#23
post #3

One of Jia’s followers on GitHub is form Eastern Europe. Edit: it’s a meme. Apparently. I feel like an old man. > illia-git This user is suspected to be a part of an online ransomware organization. Please report any suspicious activity to GitHub security. Poland

[deleted]

Re: XZ Backdoor: Times, damned times, and scams

#24
I suggest not putting a UTC+8 timezone graph as header image, when the conclusion is he's likely from Eastern Europe (not saying you should put one showing EET timezone instead).

I understand that people should read the full article instead of drawing any conclusion from a mere image, but lots of people don't (hence why clickbait works). I also think it's a little tasteless, if not misleading.

Disclaimer: I'm a Chinese.

Re: XZ Backdoor: Times, damned times, and scams

#25

Poor Jia. Two whole years of work down the drain. If you're reading this Jia, remember that you miss 100% of the shots you don't take. Chin up, brother.

Who knows how many alter egos the individual behind that online personality has, and what other projects they poisoned through those.

Re: XZ Backdoor: Times, damned times, and scams

#26
post #18
post #5

Shame on me for not reading more before my now removed comment. Shout-out for doing this level of analysis and guessing, as with everything in this incident, fascinating and tantalizing to wonder about. It is interesting, at least one of the things listed as suspicious is something I do with some frequency. I will sometimes work on what is logically three commits and not chunk them out until the very end. A bit rando…

> A bit random, but has there been speculation on why this seemed to only target rpm/deb packaging? I don't think much speculation is needed. RPM and deb catches every Enterprise Linux distribution, to the best of my knowledge. rpm catches Red Hat and all derivatives like CentOS, Alma Linux etc, as well as SuSE, Amazon Linux, and even Microsoft's Mariner Linux (now renamed Azure Linux). deb catches Debian and Ubuntu.…

Sure, but why go to the effort to exclude others? Did they think it would help avoid detection on systems that they didn't care to backdoor?

Re: XZ Backdoor: Times, damned times, and scams

#27
post #6

FBI could subpoena GitHub for IP addresses.

Considering what the account was up to I sincerely doubt it was being used without Tor or a VPN.

Probably; but ask Ross Ulbricht how easy it is to screw that up.

The thing is you only need to make a mistake once.

Post reply on HN