> In the cybersecurity world, a database engineer inadvertently finding a backdoor in a core Linux feature is a little like a bakery worker who smells a freshly baked loaf of bread, senses something is off and correctly deduces that someone has tampered with the entire global yeast supply. These kind of analogies are always a bit of an eye roll for me but I’ll grant a few points for creativity here
Andres Freund and the xz backdoor
21–28 of 28 posts
Re: Andres Freund and the xz backdoor
#22> In the cybersecurity world, a database engineer inadvertently finding a backdoor in a core Linux feature is a little like a bakery worker who smells a freshly baked loaf of bread, senses something is off and correctly deduces that someone has tampered with the entire global yeast supply. These kind of analogies are always a bit of an eye roll for me but I’ll grant a few points for creativity here
Re: Andres Freund and the xz backdoor
#23> Engineers have been circulating an old, famous-among-programmers web comic about how all modern digital infrastructure rests on a project maintained by some random guy in Nebraska. (In their telling, Mr. Freund is the random guy from Nebraska.) Huh, my take was that the "guy in Nebraska" was Lasse Collin, the original xz maintainer. Am I alone in that?
Re: Andres Freund and the xz backdoor
#24> In the cybersecurity world, a database engineer inadvertently finding a backdoor in a core Linux feature is a little like a bakery worker who smells a freshly baked loaf of bread, senses something is off and correctly deduces that someone has tampered with the entire global yeast supply. These kind of analogies are always a bit of an eye roll for me but I’ll grant a few points for creativity here
Or someone finding a $.75 accounting error, and uncovering an international East-German hacker ring.
Re: Andres Freund and the xz backdoor
#25> Engineers have been circulating an old, famous-among-programmers web comic about how all modern digital infrastructure rests on a project maintained by some random guy in Nebraska. (In their telling, Mr. Freund is the random guy from Nebraska.) Huh, my take was that the "guy in Nebraska" was Lasse Collin, the original xz maintainer. Am I alone in that?
Re: Andres Freund and the xz backdoor
#26Re: Andres Freund and the xz backdoor
#27In an otherwise well written and accessible article, I found the naming of example nations gratuitous: > some researchers believe only a nation with formidable hacking chops, such as Russia or China, could have attempted it. … or the US, UK, Israel, Germany, France, Canada, Australia, DPRK, Japan, etc, and the security offence companies that work as a supply chain for such nations in provision of embedded exploits. I…
Israel has shown in the past, with Stuxnet, that they have the skill, the patience, and the will. Same for Russia with Solarwinds.
If Jia Tan was using a FIDO/U2F key, it would be nice if someone would publish its public component so others can check for any traces of its use, but I honestly don't know how those work and whether such is even possible.
[Edited to add Russia to my personal list of countries I suspect. Something about the "misoeater91" name kinda suggests Russia to me somehow...]
Re: Andres Freund and the xz backdoor
#28> Engineers have been circulating an old, famous-among-programmers web comic about how all modern digital infrastructure rests on a project maintained by some random guy in Nebraska. (In their telling, Mr. Freund is the random guy from Nebraska.) Huh, my take was that the "guy in Nebraska" was Lasse Collin, the original xz maintainer. Am I alone in that?
Why is the NY Times afraid to namedrop XKCD :( https://xkcd.com/2347/