Live data from Hacker News

The xz sshd backdoor rabbithole goes quite a bit deeper

twitter.com

31–40 of 310 posts

Re: The xz sshd backdoor rabbithole goes quite a bit deeper

#31
post #24

Earlier quoted context omitted.

No thanks, I support an open web.

Ignoring the closed web is not the same as supporting the open web. I support whatever mirrors and tools get closed knowledge into the open. (Edited to remove snark.)

And yet a short time later: "Instance has been rate limited. Use another instance or try again later."

Re: The xz sshd backdoor rabbithole goes quite a bit deeper

#32

The sophistication here is really interesting. And it all got caught because of a fairly obvious perf regression. It reminds of a quote I heard in one of those "real crime" shows: "There's a million ways to get caught for murder, and if you can think of half of them, you're a genius."

I can believe it’s because it was a team behind the account. Someone developed the feature and another more careless or less experienced one integrated it. Another one possibly managing sock puppets and interacting in comments and PRs.

Re: The xz sshd backdoor rabbithole goes quite a bit deeper

#35
post #24

Earlier quoted context omitted.

No thanks, I support an open web.

Ignoring the closed web is not the same as supporting the open web. I support whatever mirrors and tools get closed knowledge into the open. (Edited to remove snark.)

> Choosing ignorance over knowledge

If there's some piece of knowledge that's absolutely, positively critical to my life, it will exist somewhere that actually matters, not on Twitter.

Re: The xz sshd backdoor rabbithole goes quite a bit deeper

#37
post #7

The sophistication here is really interesting. And it all got caught because of a fairly obvious perf regression. It reminds of a quote I heard in one of those "real crime" shows: "There's a million ways to get caught for murder, and if you can think of half of them, you're a genius."

Maybe I’m just being naive or too trusting, but this is sort of what I think when folks are getting worried about other backdoors like this in the wild. Is it that they just got unlucky to get caught, or is this type of attack just too hard to pull off in practice? I’d like to think the later. But, we really don’t know.

I feel the same way. It is too much complexity in one place, it couldn't work without hiccups.

Re: The xz sshd backdoor rabbithole goes quite a bit deeper

#39

The sophistication here is really interesting. And it all got caught because of a fairly obvious perf regression. It reminds of a quote I heard in one of those "real crime" shows: "There's a million ways to get caught for murder, and if you can think of half of them, you're a genius."

Yet most murders go unsolved.

Re: The xz sshd backdoor rabbithole goes quite a bit deeper

#40
post #20

Without having a Twitter account I have a really hard time following these threads. Is there some write up? Edit : Check comments. Yes, the backdoor hasn't been decompiled/reverse engineered yet. But it feels like clickbait to say : "It goes deeper"... Obviously. Nobody knows what it fully does yet. There was no assumption of knowing what it did.

Short summary is that it allows auth bypass, not just RCE.
Post reply on HN