Live data from Hacker News

The xz sshd backdoor rabbithole goes quite a bit deeper

twitter.com

201–210 of 310 posts

Re: The xz sshd backdoor rabbithole goes quite a bit deeper

#201
post #167

Earlier quoted context omitted.

> However, I believe that he is actually from somewhere in the UTC+02 (winter)/UTC+03 (DST) timezone, which includes Eastern Europe (EET), but also Israel (IST) https://rheaeve.substack.com/p/xz-backdoor-times-damned-time...

> but also Israel (IST) I had the same thought myself initially, but the analysis suggests a work-week that includes Fri, which precludes Israel (where the work week is Sun-Thu and not Mon-Fri), as well as celebrating Christmas and New Year's which are not official holidays in Israel. It isn't uncommon for younger people to take a day off for New Year's since it is an excuse to party, or for Jews with eastern Europea…

and I believe someone pointed out that there were commits on yom kippur? that is a day basically no one works. The skies are closed, the roads are empty and everyone is bicycling on all the available streets, including highways.

Re: The xz sshd backdoor rabbithole goes quite a bit deeper

#202
I often wonder with these sort of things, where there are lots of write-ups by geeks who dive-deep into the details, why do people say "This has to be state sponsored!", "Look at the timestamps! Irrefutable proof!"

Yes this was sneaky and yes this was a "slow burn" but is there really anything in the xz case that requires more than just a single competent person? Anything that requires state-level of sponsorship? The fact that random individuals online are able to dissect it and work things out suggests that it is comprehendible by a single person.

What is to say it that this was not just one smart-yet-disgruntled person acting alone?

Re: The xz sshd backdoor rabbithole goes quite a bit deeper

#203

I often wonder with these sort of things, where there are lots of write-ups by geeks who dive-deep into the details, why do people say "This has to be state sponsored!", "Look at the timestamps! Irrefutable proof!" Yes this was sneaky and yes this was a "slow burn" but is there really anything in the xz case that requires more than just a single competent person? Anything that requires state-level of sponsorship? The…

There is nothing. Nobody has any idea who he is

Re: The xz sshd backdoor rabbithole goes quite a bit deeper

#204

I often wonder with these sort of things, where there are lots of write-ups by geeks who dive-deep into the details, why do people say "This has to be state sponsored!", "Look at the timestamps! Irrefutable proof!" Yes this was sneaky and yes this was a "slow burn" but is there really anything in the xz case that requires more than just a single competent person? Anything that requires state-level of sponsorship? The…

I agree.

The hack took someone with a lot of skills, determination and time.

But doesn't that describe a significant portion of open source developers?

There is also clear motivation. Wouldn't the exploit have been worth many millions on the black market?

Re: The xz sshd backdoor rabbithole goes quite a bit deeper

#205
post #14

The weird thing about this one is how it seems super professional in some ways, and rather amateur in others. Professional in the sense of spending a long time building up an identity that seemed trustworthy enough to be made maintainer of an important package, of probably involving multiple people in social manipulation attacks, of not leaking the true identity and source of the attack, and the sophistication and ob…

We could be faced with a form of Survivorship Bias here[0]. I find that thought rather chilling. [0] https://en.wikipedia.org/wiki/Survivorship_bias

There was a recent Dwarkesh Patel interview of Dario Amodei, CEO of Anthropic, who now have ex. national security people on their staff. He said that the assumption is that if a tech company has 10,000 or more employees then not only will you almost certainly have leakers, but there is also a high likelihood there is an actual spy among your staff. This is why they use need-to-know compartmentalism, etc.

I wonder what our success rate is in identifying industrial spies? 50%?

Re: The xz sshd backdoor rabbithole goes quite a bit deeper

#206
post #14

The weird thing about this one is how it seems super professional in some ways, and rather amateur in others. Professional in the sense of spending a long time building up an identity that seemed trustworthy enough to be made maintainer of an important package, of probably involving multiple people in social manipulation attacks, of not leaking the true identity and source of the attack, and the sophistication and ob…

IIRC, according to Andres Freund the perf regression only happened in machines using the -fno-omit-frame-pointer setting, which was not the default at that point.

Re: The xz sshd backdoor rabbithole goes quite a bit deeper

#207

The sophistication here is really interesting. And it all got caught because of a fairly obvious perf regression. It reminds of a quote I heard in one of those "real crime" shows: "There's a million ways to get caught for murder, and if you can think of half of them, you're a genius."

IIRC, the perf regression only happened if the code was compiled with -fno-omit-frame-pointer, which was not the default. https://mastodon.social/@AndresFreundTec/112187000944648334

Re: The xz sshd backdoor rabbithole goes quite a bit deeper

#208
post #14

The weird thing about this one is how it seems super professional in some ways, and rather amateur in others. Professional in the sense of spending a long time building up an identity that seemed trustworthy enough to be made maintainer of an important package, of probably involving multiple people in social manipulation attacks, of not leaking the true identity and source of the attack, and the sophistication and ob…

For all we know earlier operations may have been high quality (and still undetected), this one for some reason may have been comparatively not that important and the actor decided to cut costs.

Re: The xz sshd backdoor rabbithole goes quite a bit deeper

#209
post #166

Earlier quoted context omitted.

You probably have too high expectations when you hear the "state-sponsored" part. Every large organization will inevitably end up like any other. They also have bureaucracy, deadlines, production cycle, poor communication between teams, the recent iOS "maybe-a-backdoor" story also shows that they don't always care about burning the vulnerabilities because they amassed a huge pile of them.

Welp. Ok, well now my newest worst nightmare is a jira board with tickets for "Iran" and "North Korea" stuck in the wrong column and late-night meetings with "product" about features.

The realization that there IS NOT an all powerful super intelligent cabal running everything is the worst one.

What we have is an Illuminati that is using Jira. :(

Re: The xz sshd backdoor rabbithole goes quite a bit deeper

#210
post #164
post #14

The weird thing about this one is how it seems super professional in some ways, and rather amateur in others. Professional in the sense of spending a long time building up an identity that seemed trustworthy enough to be made maintainer of an important package, of probably involving multiple people in social manipulation attacks, of not leaking the true identity and source of the attack, and the sophistication and ob…

This tracks with other nation state sponsored attack patterns. I've had that same reaction before. Most APTs are like this but some Chinese,US and Russian APTs are so well funded, every aspect of their attacks is impressive. Many hackers who work for nation states also have side gigs as crimeware/ransomgang members or actual pentesting jobs. Reminds me of apt3/boyusec: https://www.bleepingcomputer.com/news/security/c…

> It still boggles my mind that americans are against banning companies like huawei and bytedance. The MSS and PLA don't mess around.

The problem is that many others would have as much reason to bann US companies. I mean the US has a much more extensive history of using their security apparatus both for intelligence and economic means even against their allies.

Now if everyone bans everyone else we will let the world economy grind to a halt pretty quickly.

Post reply on HN