Live data from Hacker News

The xz sshd backdoor rabbithole goes quite a bit deeper

twitter.com

301–310 of 310 posts

Re: The xz sshd backdoor rabbithole goes quite a bit deeper

#301
post #91

Earlier quoted context omitted.

What do you mean by "package managers not taking source from the right place"?

I assume they are advocating for package managers to preferably grab signed git tags from repositories rather than download tarballs. The backdoor relied on the source in the tarballs being different from the git tag, adding additional script code. This is common for projects that uses GNU autotools as build system; maintainers traditionally run autoconf so that users don't have to and ship the results in the tarball…

I think saying that the backdoor relied on it is too strong. The changes were obfuscated enough that it's unlikely anyone would have noticed if they were pushed to git, not doing that is just an additional layer of safety.

Re: The xz sshd backdoor rabbithole goes quite a bit deeper

#302
post #222

Earlier quoted context omitted.

I would be interested in semantic analysis of the communication from the involved online personas, similar to what was done for Satoshi, to point to a cultural direction. Would also be interesting to see if there were semantic style differences over time pointing to different people acting as the personas. Since it would be quite a lot of code that has been committed as well, would also be interesting to see if code…

There is nothing of value to gain from such analysis. Even if evidence turns up, it would be even more flimsy than graphology.

Since when does does satisfying curiosity not provide any value. This has the potential to be a real life spy story ffs. Yeah you won't know anything for sure, that doesn't make this any less interesting.

Re: The xz sshd backdoor rabbithole goes quite a bit deeper

#303
post #290
post #289

Earlier quoted context omitted.

We are quite far in a meta-discussion. Even less useful.

And... you continue to discuss it. I'm going to stop now. You have quite effectively proven the opposite of your position.

No you see: you are not allowed to talk about hings if other users think it's unproductive. Cease having fun immediately.

Re: The xz sshd backdoor rabbithole goes quite a bit deeper

#304

Earlier quoted context omitted.

I wasn't even thinking of f-droid and I didn't mention them in my comment at all so I'm not sure why you think I'm linking the two when I didn't even mention them. https://nordvpn.com/blog/fbi-honeypot/ Signal could do more to be open with the build process, but opening the door to third party clients is opening the door for APTs to release backdoored Signal clients.

F-Droid was mentioned in the very first comment of this thread, and all of the issues linked in github. Seems like you haven't read them, and bringing other parties into the discussion seems like a distraction. > but opening the door to third party clients is opening the door for APTs to release backdoored Signal clients. Signal's source code is already public. APTs (or anyone who doesn't care about violating laws) c…

I'm sorry for not doing all of my homework before responding, but what's with you and the word strawman? It it your homework assignment to write that word seven times on the Internet or something? Say it a couple more times, it'll really help get your point across.

Getting Signal from anywhere else other than them opens up the door for someone to sneak in some code. I am not, in any way, insinuating that fdroid would intentionally do such a thing.

Re: The xz sshd backdoor rabbithole goes quite a bit deeper

#305

Earlier quoted context omitted.

F-Droid was mentioned in the very first comment of this thread, and all of the issues linked in github. Seems like you haven't read them, and bringing other parties into the discussion seems like a distraction. > but opening the door to third party clients is opening the door for APTs to release backdoored Signal clients. Signal's source code is already public. APTs (or anyone who doesn't care about violating laws) c…

I'm sorry for not doing all of my homework before responding, but what's with you and the word strawman? It it your homework assignment to write that word seven times on the Internet or something? Say it a couple more times, it'll really help get your point across. Getting Signal from anywhere else other than them opens up the door for someone to sneak in some code. I am not, in any way, insinuating that fdroid would…

> Getting Signal from anywhere else other than them opens up the door for someone to sneak in some code.

Incorrect. See David A. Wheeler's seminal paper https://dwheeler.com/trusting-trust/

An easy way to avoid talking about strawmen is to avoid bringing one into the conversation. Something to think about.

Re: The xz sshd backdoor rabbithole goes quite a bit deeper

#306

Earlier quoted context omitted.

> With proper error handling, that's about 50 lines of C code. Writing proper error handling in C is a very tedious and error prone task. So it doesn't surprise me that people would rather call another library instead.

You think error handling for a socket connection + send is outside the capabilities of those developing sshd?

You think every time people call an external library to save their effort is a proof of their lack of capabilities?

Re: The xz sshd backdoor rabbithole goes quite a bit deeper

#308
post #290
post #289

Earlier quoted context omitted.

We are quite far in a meta-discussion. Even less useful.

And... you continue to discuss it. I'm going to stop now. You have quite effectively proven the opposite of your position.

We have both moved as far from the original topic as possible.
Post reply on HN