Live data from Hacker News

The xz sshd backdoor rabbithole goes quite a bit deeper

twitter.com

271–280 of 310 posts

Re: The xz sshd backdoor rabbithole goes quite a bit deeper

#271

Earlier quoted context omitted.

Which is to say, they don't trust 3rd parties to build the software without backdoors. Can't say I blame them. Allowing for 3rd party clients opens Signal to backdoored clients. I know you think that people would only make 3rd-party clients for good, and not do bad things with that power, and no one would be foolish enough to download Definitely-not-backdoored-Signal-client from hackers.ru, but I'm pretty sure that's…

> An APT could exploit a Pegasus-like zero-day in iOS and install a replacement Nothing about the way Signal currently does things prevents this from happening today. Disallowing third party builds only serves to reduce eyes on the build tooling, which we've learned is a great place to hide backdoors. Equating F-Droid with hackers.ru is a distasteful strawman. F-Droid appear to run as transparent and credible a distr…

I wasn't even thinking of f-droid and I didn't mention them in my comment at all so I'm not sure why you think I'm linking the two when I didn't even mention them.

https://nordvpn.com/blog/fbi-honeypot/

Signal could do more to be open with the build process, but opening the door to third party clients is opening the door for APTs to release backdoored Signal clients.

Re: The xz sshd backdoor rabbithole goes quite a bit deeper

#272
post #207

The sophistication here is really interesting. And it all got caught because of a fairly obvious perf regression. It reminds of a quote I heard in one of those "real crime" shows: "There's a million ways to get caught for murder, and if you can think of half of them, you're a genius."

IIRC, the perf regression only happened if the code was compiled with -fno-omit-frame-pointer, which was not the default. https://mastodon.social/@AndresFreundTec/112187000944648334

Fedora and Ubuntu both enable frame pointers / disable -fomit-frame-pointer by default now[1]. That’s quite recent news in comparison to the backdoor’s history, admittedly.

[1] https://www.brendangregg.com/blog/2024-03-17/the-return-of-t...

Re: The xz sshd backdoor rabbithole goes quite a bit deeper

#273

Earlier quoted context omitted.

> An APT could exploit a Pegasus-like zero-day in iOS and install a replacement Nothing about the way Signal currently does things prevents this from happening today. Disallowing third party builds only serves to reduce eyes on the build tooling, which we've learned is a great place to hide backdoors. Equating F-Droid with hackers.ru is a distasteful strawman. F-Droid appear to run as transparent and credible a distr…

I wasn't even thinking of f-droid and I didn't mention them in my comment at all so I'm not sure why you think I'm linking the two when I didn't even mention them. https://nordvpn.com/blog/fbi-honeypot/ Signal could do more to be open with the build process, but opening the door to third party clients is opening the door for APTs to release backdoored Signal clients.

F-Droid was mentioned in the very first comment of this thread, and all of the issues linked in github. Seems like you haven't read them, and bringing other parties into the discussion seems like a distraction.

> but opening the door to third party clients is opening the door for APTs to release backdoored Signal clients.

Signal's source code is already public. APTs (or anyone who doesn't care about violating laws) can already produce and disseminate their own builds. There are no technical protections in place to stop them - nor do I know of any which could. The only people who can't currently distribute their own builds are the law abiding good guys trying to build secure software distributions. I'm not sure why you're confused about this, but your assertion that Signal making legal allowances for third party builds adds anything to the capabilities of APTs demonstrates a misunderstanding of what is already available and the (strictly legal) limitations Signal has placed on 3rd parties with regard to distributing independently verifiable builds.

Please take some time to read and understand the github issues, instead of continuing to assert falsehoods or introduce strawmen.

Re: The xz sshd backdoor rabbithole goes quite a bit deeper

#274

Earlier quoted context omitted.

and I believe someone pointed out that there were commits on yom kippur? that is a day basically no one works. The skies are closed, the roads are empty and everyone is bicycling on all the available streets, including highways.

Israel isn't home only for Jewish people who don't work on Yom Kippur, there are significant populations of both Muslims and Chirstians I don't think that you can rule out any country based on email and commit timestamps, the attacker could have been further east and had a late work day, or further east with an early work day

I hate to defend Israel’s work week here, because it sucks to an unimaginable extent, but while you’re free not to observe Jewish holidays in Israel, unless you’re lucky to live in one of a handful of places you’ll struggle heavily to get anything done on Fri or Sat. If you try, you’ll find nothing works during most of that time including public transport—except for Friday morning when you’re going to have to scramble to get stuff done so you don’t run out of food before Sunday morning. On Yom Kippur, even driving around in your own car is going to get you fined. And, of course, nearly nothing managed by the governments works on the weekend or holidays, except for the military.

(I wouldn’t put it past the intelligence services to keep working during official holidays as a form of obfuscation, mind you. I just wanted to point out that it isn’t as straightforward a deal as Christians—or atheists for that matter—existing: Israel sure makes daily life hard for them.)

Re: The xz sshd backdoor rabbithole goes quite a bit deeper

#275

Earlier quoted context omitted.

Israel isn't home only for Jewish people who don't work on Yom Kippur, there are significant populations of both Muslims and Chirstians I don't think that you can rule out any country based on email and commit timestamps, the attacker could have been further east and had a late work day, or further east with an early work day

I hate to defend Israel’s work week here, because it sucks to an unimaginable extent, but while you’re free not to observe Jewish holidays in Israel, unless you’re lucky to live in one of a handful of places you’ll struggle heavily to get anything done on Fri or Sat. If you try, you’ll find nothing works during most of that time including public transport—except for Friday morning when you’re going to have to scrambl…

I am an Israeli, and I agree with you. I just wanted to point out that trying to speculate a location for the attacker based on what days they worked isn't going to be remotely accurate

Speaking of innacurate things, since the actual XZ git.repository isn't hosted on GitHub, could there be logs of which IP address the attacker was operating from?

Re: The xz sshd backdoor rabbithole goes quite a bit deeper

#276

Earlier quoted context omitted.

Very large companies are definitely at the mercy of governments. Just look at how they are bending over backwards to comply with DMA etc. So, it is not at all inconceivable that they are forced to put backdoors into their product by the governments.

Except Apple is known for having very publicly fought the FBI’s attempt to force a backdoor into iOS. https://en.m.wikipedia.org/wiki/Apple–FBI_encryption_dispute

That’s true. On the other hand, Apple isn’t some kind of Borg like swarm intelligence. While Apple’s upper management doesn’t want back doors in their products, someone in middle management might have come to a different opinion.

Re: The xz sshd backdoor rabbithole goes quite a bit deeper

#277

Earlier quoted context omitted.

Doesn't your data prove the opposite point? There are so many vulnerabilities and so few people looking for them that even the thirty year old ones have barely been found. A healthy feedback loop would have trended the average age of each vulnerability at the time of detection to be *short".

Most backdoors that are found are really obvious garbage. Like hardcoded credentials or keys in appliances.

This also had hardcoded credentials, just quite well obfuscated.

So I learned yesterday what a Trie is.

https://en.wikipedia.org/wiki/Trie

Re: The xz sshd backdoor rabbithole goes quite a bit deeper

#278
post #263
post #223

Earlier quoted context omitted.

We are all speculating .

So this whole thread is based on the premise that the OP was using the formal definition of "discuss" rather than the informal one? Which is almost certainly not true? Ya'll must be super fun at parties.

Either kind of discussion is useless since the "evidence" (timezone IDs in strings that are not required to have any relation whatsoever with reality) is flimsy to begin with.

Re: The xz sshd backdoor rabbithole goes quite a bit deeper

#279
post #254

Earlier quoted context omitted.

US companies? I'm with you, no! Foreign companies, absolutley. Even the suspicion of malicious abuse should be enough to ban a foreign company. Foreign persons and entities have no rights in the US and our government owes them as much explanation as they give us when they ban US companies on a whim.

> Foreign persons and entities have no rights in the US "Yes, immigrants are protected by the U.S. Constitution. The brief answer is “Yes.” When it comes to key constitutional provisions like due process and equal treatment under the law, the U.S. Constitution applies to all persons – which includes both documented and undocumented immigrants – and not just U.S. citizens. Outside the context of immigration policy, th…

We are not talking about immigrants, we are talking about foreign entities, as in not immigrated to the US. The Chinese communist party and the owners of bytedance have not immigrated to the US.

I don't get the point if the mental gymnastics here. We both know of an active threat to americans by a foreign entity. Companies are not people and being able to create and operate a company is not a protected right. Matter of fact, regulating interstate commerce is an explicit right of the government.

For example, you can't transport alcohol across state lines. The government doesn't need a good reason for that regulation, it's their constitutional right.

In this case, simply reciprocating china's bans on US companies would have done the trick.

Honestly, the US government should move to ban all trade with China within a decade or so.

As for bytedance, the government is not claiming chinese immigrants can't own it, they are claiming that the China based owners of bytedance have to sell their stake in the company since any company in China is under the influence of the MSS as evidenced by many examples, the boyusec/apt3 example I mentioned being one.

Post reply on HN