Yikes! Do you have any info on the individual's background or possible motivations?
There is zero web presence for this person and associated email address. Looks more likely a fake identity than compromised account.
Backdoor in upstream xz/liblzma leading to SSH server compromise
321–330 of 1001 posts
Re: Backdoor in upstream xz/liblzma leading to SSH server compromise
#322Quite ironic: The most recent commit in the git repo is "Simplify SECURITY.md", committed by the same Github account which added the backdoor. https://github.com/tukaani-project/xz/commit/af071ef7702debe...
Re: Backdoor in upstream xz/liblzma leading to SSH server compromise
#323Everybody here In jumping into the pure malice bandwagon, I have a better hypothesis. Abandonment and inaction, the actual developers of these tools are elsewhere, oblivious to this drama, trying to make living because most of the time you are not compensated nor any corporation cares about making things sustainable at all. This is the default status of everything your fancy cloud depends on underneath. An attacker t…
Except that doesn't match reality. Someone has worked on xz for several years. Are you saying that this somewhat active contributor was likely actively contributing, then all of a sudden stopped, also stopped paying attention, and also allowed their account to be compromised or otherwise handed it over to a nefarious party? That fails the sniff test.
Re: Backdoor in upstream xz/liblzma leading to SSH server compromise
#324Re: Backdoor in upstream xz/liblzma leading to SSH server compromise
#325Earlier quoted context omitted.
Every single commit this person ever did should immediately be rolled back in all projects.
It's weird and disturbing that this isn't the default perspective.
Damage wise, most orgs aren't going to be hurt much by NSA or the Chinese equivalent getting access, but a Nigerian criminal gang? They're far more likely to encrypt all your files and demand a ransom.
Re: Backdoor in upstream xz/liblzma leading to SSH server compromise
#326Re: Backdoor in upstream xz/liblzma leading to SSH server compromise
#327Funny how Lasse Collin started to ccing himself and Jia Tan from 2024-03-20 (that was a day of tons of xz kernel patches), he never did that before. :) https://lore.kernel.org/lkml/20240320183846.19475-2-lasse.co...
Also interesting, to me, how the GMail account for the backdoor contributor ONLY appears in the context of "XZ" discussions. Google their email address. Suggests a kind of focus, to me, and a lack of reality / genuineness.
Re: Backdoor in upstream xz/liblzma leading to SSH server compromise
#328Jai Tan's commit history on his github profile suggests he took off for Christmas, new years, and spring break. I smell an American.
Another thing would be to examine everything ever written by the user for linguistic clues. This might point towards particular native languages or a particular variant of English or towards there being several different authors.
Re: Backdoor in upstream xz/liblzma leading to SSH server compromise
#329Funny how Lasse Collin started to ccing himself and Jia Tan from 2024-03-20 (that was a day of tons of xz kernel patches), he never did that before. :) https://lore.kernel.org/lkml/20240320183846.19475-2-lasse.co...
It looks like someone may have noticed a unmaintained or lightly maintained project related to various things, and moved to take control of it.
Otherwhere in the discussion here someone mentions the domain details changed; if you have control of the domain you have control of all emails associated with it.
Re: Backdoor in upstream xz/liblzma leading to SSH server compromise
#330The discussion to upload it to Debian is interesting on its own https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1067708
Wow, that's a lot of anonymous accounts adding comments there urging for a fast merge! And this "Hans Jansen" guy is apparently running around salsa.debian.org pushing for more updates in other projects as well: https://salsa.debian.org/users/hjansen/activity
Just FYI, krygorin4545@proton.me (the latest message before the upload) was created Tue Mar 26 18:30:02 UTC 2024, about an hour earlier than the message was posted.
Proton generates PGP key upon creating the account, with the real datetime of the key (but the key does not include the timezone).