Earlier quoted context omitted.
There was a discussion about this recently saying that it was highly unlikely. All the source was in Git and every git commit references the previous commit, making it highly challenging to modify an old commit without also modifying the commit id. More details: http://archive.is/Khq7R
Yes, it's unlikely they modified the source in git.. But it's possible they were able to download a copy and modify it locally... Possibly adding comments to document certain blocks of code.. Or adding unofficial patches for zfs support... Or worse..
Who rooted kernel.org servers two years ago?
21–30 of 50 posts
Re: Who rooted kernel.org servers two years ago?
#22- Jon Corbet reporting on a talk by H. Peter Anvin, https://lwn.net/Articles/464233/
Re: Who rooted kernel.org servers two years ago?
#23So let's speculate about what the article almost-but-doesn't-quite propose: The NSA, or related parties, was responsible for the breach. There was an investigation and postmortem, but because of an NSL or other gag-type order, they couldn't accurately publish what they discovered. So they figured that not releasing a report was better than releasing a report that either intentionally misled or pretended not to have f…
> WELCOME TO THE CRAPTOPOCLYPSE: From now on, every security discussion wastes 15 minutes on “but did the NSA DO IT?!?!’ no matter how absurd. https://twitter.com/grahamvsworld/status/375793987992715264 I'd be more curious to see the actual report before speculating.
Could be they're lazy. Could be they're embarrassed. Could be they're legally prohibited from reporting it -- which in turn could be due to a NSL.
Lots of "could be". But not entirely crazy to list all the possibilities... while waiting for the report, which we can probably all agree ought to be released by now.
Re: Who rooted kernel.org servers two years ago?
#24I'm not saying that it is, but compromising Git is certainly the sort of thing which would occur to a state sponsored espionage agency. And if one were seeking to compromise the Linux toolchain, it would certainly be a very attractive link. So attractive that not including it in a multi-vector attack might be considered grossly unprofessional.
Re: Who rooted kernel.org servers two years ago?
#25Earlier quoted context omitted.
> WELCOME TO THE CRAPTOPOCLYPSE: From now on, every security discussion wastes 15 minutes on “but did the NSA DO IT?!?!’ no matter how absurd. https://twitter.com/grahamvsworld/status/375793987992715264 I'd be more curious to see the actual report before speculating.
I think the point was, why hasn't the report been released yet, 2 years later? Could be they're lazy. Could be they're embarrassed. Could be they're legally prohibited from reporting it -- which in turn could be due to a NSL. Lots of "could be". But not entirely crazy to list all the possibilities... while waiting for the report, which we can probably all agree ought to be released by now.
Re: Who rooted kernel.org servers two years ago?
#26A feature of civilian security is that "It was restored from Git" is doesn't immediately spark a concern that Git could be compromised. I'm not saying that it is, but compromising Git is certainly the sort of thing which would occur to a state sponsored espionage agency. And if one were seeking to compromise the Linux toolchain, it would certainly be a very attractive link. So attractive that not including it in a mu…
Yeah, there are exceptions, all of them proprietrary. There is no reason to trust GIT less just because some companies can make even version control hard.
Re: Who rooted kernel.org servers two years ago?
#27That said, as I recall the "hack" was a lot less impressive than it seemed (some folks in Google's Linux team were administrators of kernel.org). I do wonder about the lack of a definitive online after action report though. Seems someone dropped the ball on that one.
Re: Who rooted kernel.org servers two years ago?
#28Weird parallel between the NSA revelations and the Global Warming movement, every odd weather event is attributed to global warming, every odd security event it attributed to the NSA. That said, as I recall the "hack" was a lot less impressive than it seemed (some folks in Google's Linux team were administrators of kernel.org). I do wonder about the lack of a definitive online after action report though. Seems someon…
Re: Who rooted kernel.org servers two years ago?
#29So let's speculate about what the article almost-but-doesn't-quite propose: The NSA, or related parties, was responsible for the breach. There was an investigation and postmortem, but because of an NSL or other gag-type order, they couldn't accurately publish what they discovered. So they figured that not releasing a report was better than releasing a report that either intentionally misled or pretended not to have f…
The report hasn't been disclosed because they are under legal obligation not to disclose.
The report hasn't been disclosed because they are corrupt.
The report hasn't been disclosed because they are embarrassed.
The report hasn't been disclosed because they are lazy.
The report hasn't been disclosed because they are incompetent.
What other possibilities exist? Which one is most likely?
Re: Who rooted kernel.org servers two years ago?
#30Earlier quoted context omitted.
I think the point was, why hasn't the report been released yet, 2 years later? Could be they're lazy. Could be they're embarrassed. Could be they're legally prohibited from reporting it -- which in turn could be due to a NSL. Lots of "could be". But not entirely crazy to list all the possibilities... while waiting for the report, which we can probably all agree ought to be released by now.
My bet is on "lazy", but I think it's much easier to buy into the NSL explanation than the embarrassement one.