Live data from Hacker News

The xz sshd backdoor rabbithole goes quite a bit deeper

twitter.com

211–220 of 310 posts

Re: The xz sshd backdoor rabbithole goes quite a bit deeper

#211
post #14

The weird thing about this one is how it seems super professional in some ways, and rather amateur in others. Professional in the sense of spending a long time building up an identity that seemed trustworthy enough to be made maintainer of an important package, of probably involving multiple people in social manipulation attacks, of not leaking the true identity and source of the attack, and the sophistication and ob…

The maintainer account (the identity) could have been sold to a third party. There are secondary markets [1] for this.

[1] https://ogusers.gg/ is the largest clear net marketplace for buying and selling usernames on popular sites

Re: The xz sshd backdoor rabbithole goes quite a bit deeper

#212
post #166

Earlier quoted context omitted.

Welp. Ok, well now my newest worst nightmare is a jira board with tickets for "Iran" and "North Korea" stuck in the wrong column and late-night meetings with "product" about features.

The realization that there IS NOT an all powerful super intelligent cabal running everything is the worst one. What we have is an Illuminati that is using Jira. :(

Who do you think wrote Jira?

Re: The xz sshd backdoor rabbithole goes quite a bit deeper

#213
post #45
post #28

Earlier quoted context omitted.

There are thousands of ways that performance can be impacted. No matter how good you are at developing, there will be a workload that would have a performance hit. Phoronix has been several times reporting issues to the Linux kernel because performance regression with their test suite. Performance tests tend to take more time than correctness tests.

Not seeing that as a point. It's probably not possible to have no performance hit whatsoever when you're checking the exact nanosecond count of every little thing. But usually nobody is doing that. It shouldn't be hard to not cause a substantial enough performance regression in SSHD logins that somebody who wasn't already monitoring that would notice and decide to dig into what's going on. I'm not sure if it's been r…

[deleted]

Re: The xz sshd backdoor rabbithole goes quite a bit deeper

#214
post #23

The sophistication here is really interesting. And it all got caught because of a fairly obvious perf regression. It reminds of a quote I heard in one of those "real crime" shows: "There's a million ways to get caught for murder, and if you can think of half of them, you're a genius."

> "There's a million ways to get caught for murder, and if you can think of half of them, you're a genius." Does "think of half" apply to the folks trying to solve murders?

That's from Body Heat, said by Mickey Rourke to William Hurt. "...you got fifty ways you're gonna fuck up. If you think of twenty-five of them, then you're a genius - and you ain't no genius." (But a million sounds closer to the truth.)

Re: The xz sshd backdoor rabbithole goes quite a bit deeper

#215

Earlier quoted context omitted.

The realization that there IS NOT an all powerful super intelligent cabal running everything is the worst one. What we have is an Illuminati that is using Jira. :(

Who do you think wrote Jira?

And WHY do you think they wrote Jira?

Re: The xz sshd backdoor rabbithole goes quite a bit deeper

#217

Earlier quoted context omitted.

The realization that there IS NOT an all powerful super intelligent cabal running everything is the worst one. What we have is an Illuminati that is using Jira. :(

Who do you think wrote Jira?

That's the joke

Re: The xz sshd backdoor rabbithole goes quite a bit deeper

#218

it's a rather good thing that this was found before it made it out broadly. Not just for obvious reason of not wanting an unknown party to have RCE on your infrastructure. I think as people keep digging they will eventually formulate a payload which will allow the backdoor to be used by anyone. As bad as it is for a single party to have access, it's much worse for any (every?) party to have access.

Isn’t that more or less impossible since the payload is a private RSA key?

If it is known to belong to a widely deployed backdoor that can't be patched away in time, then it is worth to recover the key by brute force using supercomputers. Of course, such capabilities are rather restricted to nation states.

Re: The xz sshd backdoor rabbithole goes quite a bit deeper

#220
post #14

The weird thing about this one is how it seems super professional in some ways, and rather amateur in others. Professional in the sense of spending a long time building up an identity that seemed trustworthy enough to be made maintainer of an important package, of probably involving multiple people in social manipulation attacks, of not leaking the true identity and source of the attack, and the sophistication and ob…

The tin foiler in me still suspects it could be Microsoft who planted it to make FOSS look bad.
Post reply on HN