Without having a Twitter account I have a really hard time following these threads. Is there some write up? Edit : Check comments. Yes, the backdoor hasn't been decompiled/reverse engineered yet. But it feels like clickbait to say : "It goes deeper"... Obviously. Nobody knows what it fully does yet. There was no assumption of knowing what it did.
The xz sshd backdoor rabbithole goes quite a bit deeper
241–250 of 310 posts
Re: The xz sshd backdoor rabbithole goes quite a bit deeper
#242The weird thing about this one is how it seems super professional in some ways, and rather amateur in others. Professional in the sense of spending a long time building up an identity that seemed trustworthy enough to be made maintainer of an important package, of probably involving multiple people in social manipulation attacks, of not leaking the true identity and source of the attack, and the sophistication and ob…
Libsystemd was moving to a dlopen architecture for its dependencies.
This means that the backdoor would not load as the sshd patch only used libsystemd for notify, which does not need liblzma at all.
So they IMHO gave it a last shot. It's OK if it burns as it would be useless in 3 months (or even less).
The collateral is the backdoor Binary, but given enough engineering power it will be irrelevant in 2-3 months, too.
Re: The xz sshd backdoor rabbithole goes quite a bit deeper
#243Earlier quoted context omitted.
I don't believe it's intentional for the reason you mentioned. Although it could theoretically be like that for plausible deniability, Apple's reputation is definitely more valuable than one patchable backdoor of god knows how many others. But debug backdoor is still a backdoor.
Very large companies are definitely at the mercy of governments. Just look at how they are bending over backwards to comply with DMA etc. So, it is not at all inconceivable that they are forced to put backdoors into their product by the governments.
https://en.m.wikipedia.org/wiki/Apple–FBI_encryption_dispute
Re: The xz sshd backdoor rabbithole goes quite a bit deeper
#244I often wonder with these sort of things, where there are lots of write-ups by geeks who dive-deep into the details, why do people say "This has to be state sponsored!", "Look at the timestamps! Irrefutable proof!" Yes this was sneaky and yes this was a "slow burn" but is there really anything in the xz case that requires more than just a single competent person? Anything that requires state-level of sponsorship? The…
The biggest thing for me that points to a state actor is the amount of time committed to the social engineering attack versus the expected value of the prize. A for-profit scheme built this way would be irrational, which doesn't preclude it being an irrational actor (or an individual with a motive other than profit) but does point to a state actor as a likely candidate. The total value of the prize, if successful, wo…
If you're a very skilled and dedicated hacker, what other targets do you have that can net you many millions of dollars?
> or an individual with a motive other than profit
Isn't one of the most striking things about the hacker community the extreme amounts of time and effort that are put into things that are not expected to generate any profit?
I mean, there are people who spend all their free time over several decades just digging tunnels under their property. Or build a 6502 CPU from discrete transistors. Etc.
Re: The xz sshd backdoor rabbithole goes quite a bit deeper
#245Earlier quoted context omitted.
Is it reasonable to assume a material number of cleared murders in Germany result in no charges and/or no conviction? (Genuinely curious.)
Surely it's pretty common everywhere to have at some point a suspect ('solved!') who is then released, because you lack evidence, realise it's not them, whatever. A suspect isn't necessarily convicted even if you do ultimately convict someone.
What does that mean?
Re: The xz sshd backdoor rabbithole goes quite a bit deeper
#246Earlier quoted context omitted.
Patriots for the most part suck at coding as much as everyone else.
not just at coding. as a class of people, they tend to not be the sharpest tools in the shed.
Re: The xz sshd backdoor rabbithole goes quite a bit deeper
#247The weird thing about this one is how it seems super professional in some ways, and rather amateur in others. Professional in the sense of spending a long time building up an identity that seemed trustworthy enough to be made maintainer of an important package, of probably involving multiple people in social manipulation attacks, of not leaking the true identity and source of the attack, and the sophistication and ob…
Well, there is a pretty logical explanation. Libsystemd was moving to a dlopen architecture for its dependencies. This means that the backdoor would not load as the sshd patch only used libsystemd for notify, which does not need liblzma at all. So they IMHO gave it a last shot. It's OK if it burns as it would be useless in 3 months (or even less). The collateral is the backdoor Binary, but given enough engineering po…
The only thing that makes me think this was amateurs/criminals instead of professionals is that I tend to think that professionals are more interested in post attack security.
So if the gate was closing an amateur would say, "Act now! Let's get what we can!" A professional would say, "This is all going to come to light real soon - our exploit won't be read and there's a high chance of this all falling apart. Pull out everything, cover our tracks to the degree we can and find another opportunity to pull this off."
But then again I also think on professionals would work an exploit that takes years. Criminals by their nature want a quick payout (If I had the patience for a long con I'd just get a job) a motivated individual amateurs (i.e. crazy people) rarely have a wide enough skill set.
Re: The xz sshd backdoor rabbithole goes quite a bit deeper
#248Earlier quoted context omitted.
> "There's a million ways to get caught for murder, and if you can think of half of them, you're a genius." Does "think of half" apply to the folks trying to solve murders?
Nah, it applies to the person trying to get away with the murder. People will do really, really intricate jobs of trying to cover up, then slip up because like, they leave a receipt in their car that accidentally breaks their alibi.
Re: The xz sshd backdoor rabbithole goes quite a bit deeper
#249The weird thing about this one is how it seems super professional in some ways, and rather amateur in others. Professional in the sense of spending a long time building up an identity that seemed trustworthy enough to be made maintainer of an important package, of probably involving multiple people in social manipulation attacks, of not leaking the true identity and source of the attack, and the sophistication and ob…
So the systems developer job is to build a reputation over years as we see, the security guy's job is to handle the equation group heavily encrypted/obfuscated exploits.
This would explain a mix of code quality / professionalism - multiple people, multiple roles. Of course the former "systems programmer" role need not be a full time employee. They good have motivated a white hat developer to change hats, either financially or through an offer they can't refuse.
Re: The xz sshd backdoor rabbithole goes quite a bit deeper
#250Earlier quoted context omitted.
Surely it's pretty common everywhere to have at some point a suspect ('solved!') who is then released, because you lack evidence, realise it's not them, whatever. A suspect isn't necessarily convicted even if you do ultimately convict someone.
> A suspect isn't necessarily convicted even if you do ultimately convict someone. What does that mean?
It happens loads too, frequently in high profile stuff on the news they'll have a suspect who's somehow close to it, arrest them, but then they're released once satisfied with their allibi or whatever.