I think its much more likely this was not a bad actor, given their long history of commits. It's a known fact that China will "recruit" people to operate them. A quote: > They talk to them, say my friend, I see you like our special menu. Are you from China? Are you here on a VISA? Do you have family back there? Would you like your family to stay alive? Is your loyalty to this temporary employer or is your loyalty to…
Backdoor in upstream xz/liblzma leading to SSH server compromise
331–340 of 1001 posts
Re: Backdoor in upstream xz/liblzma leading to SSH server compromise
#332Unfortunately, this is how good bad actors work: with a very long-term point of view. There is no “harmless” project any more.
I imagine it might be easier to just compromise a weakly protected account than to actual put in a 2 years long effort with real contributions. If we mandated MFA for all contributors who contribute to these really important projects then we can know with greater certainty if it was really a long con vs. a recently compromised account.
Re: Backdoor in upstream xz/liblzma leading to SSH server compromise
#333I think its much more likely this was not a bad actor, given their long history of commits. It's a known fact that China will "recruit" people to operate them. A quote: > They talk to them, say my friend, I see you like our special menu. Are you from China? Are you here on a VISA? Do you have family back there? Would you like your family to stay alive? Is your loyalty to this temporary employer or is your loyalty to…
Re: Backdoor in upstream xz/liblzma leading to SSH server compromise
#334Jai Tan's commit history on his github profile suggests he took off for Christmas, new years, and spring break. I smell an American.
Operating on a target region schedule doesn't seem particularly sophisticated, at least compared to the all the efforts put into this exploit.
Re: Backdoor in upstream xz/liblzma leading to SSH server compromise
#335Jesus! Does anyone know if Debian stable is affected?
Re: Backdoor in upstream xz/liblzma leading to SSH server compromise
#336Earlier quoted context omitted.
I think this has been in the making for almost a year. The whole ifunc infrastructure was added in June 2023 by Hans Jansen and Jia Tan. The initial patch is "authored by" Lasse Collin in the git metadata, but the code actually came from Hans Jansen: https://github.com/tukaani-project/xz/commit/ee44863ae88e377... > Thanks to Hans Jansen for the original patch. https://github.com/tukaani-project/xz/pull/53 There were…
1 week ago "Hans Jansen" user "hjansen" was created in debian and opened 8 PRs including the upgrade to 5.6.1 to xz-utils From https://salsa.debian.org/users/hjansen/activity Author: Hans Jansen - [Debian Games / empire]( https://salsa.debian.org/games-team/empire ): opened merge request "!2 New upstream version 1.17" - March 17, 2024 - [Debian Games / empire]( https://salsa.debian.org/games-team/empire ): opened mer…
Re: Backdoor in upstream xz/liblzma leading to SSH server compromise
#337I think its much more likely this was not a bad actor, given their long history of commits. It's a known fact that China will "recruit" people to operate them. A quote: > They talk to them, say my friend, I see you like our special menu. Are you from China? Are you here on a VISA? Do you have family back there? Would you like your family to stay alive? Is your loyalty to this temporary employer or is your loyalty to…
I think we should seriously consider something like a ts clearance as mandatory for work on core technologies. Many other projects, both open and closed, are probably compromised by foreign agents.
Re: Backdoor in upstream xz/liblzma leading to SSH server compromise
#338I think its much more likely this was not a bad actor, given their long history of commits. It's a known fact that China will "recruit" people to operate them. A quote: > They talk to them, say my friend, I see you like our special menu. Are you from China? Are you here on a VISA? Do you have family back there? Would you like your family to stay alive? Is your loyalty to this temporary employer or is your loyalty to…
I think we should seriously consider something like a ts clearance as mandatory for work on core technologies. Many other projects, both open and closed, are probably compromised by foreign agents.
Re: Backdoor in upstream xz/liblzma leading to SSH server compromise
#339Randomly picked https://github.com/Neustradamus and looked at all their contributions.
Interestingly enough, they got Microsoft to upgrade ([0],[1]) `vcpkg` to liblzma 5.6.0 3 weeks ago.
Re: Backdoor in upstream xz/liblzma leading to SSH server compromise
#340Earlier quoted context omitted.
I don't want to read too much into it, but the person (supposedly) submitting the PR seems to work at 1Password since December last year, as per his Linkedin. (And his Linkedin page has a link to the Github profile that made the PR).
As a 1Password user, I just got rather nervous.