Live data from Hacker News

Backdoor in upstream xz/liblzma leading to SSH server compromise

openwall.com

331–340 of 1001 posts

Re: Backdoor in upstream xz/liblzma leading to SSH server compromise

#331

I think its much more likely this was not a bad actor, given their long history of commits. It's a known fact that China will "recruit" people to operate them. A quote: > They talk to them, say my friend, I see you like our special menu. Are you from China? Are you here on a VISA? Do you have family back there? Would you like your family to stay alive? Is your loyalty to this temporary employer or is your loyalty to…

Isn't that still a "bad actor" even if they are coerced into it?

Re: Backdoor in upstream xz/liblzma leading to SSH server compromise

#332

Unfortunately, this is how good bad actors work: with a very long-term point of view. There is no “harmless” project any more.

I imagine it might be easier to just compromise a weakly protected account than to actual put in a 2 years long effort with real contributions. If we mandated MFA for all contributors who contribute to these really important projects then we can know with greater certainty if it was really a long con vs. a recently compromised account.

github already mandates MFA for members of important projects

Re: Backdoor in upstream xz/liblzma leading to SSH server compromise

#333

I think its much more likely this was not a bad actor, given their long history of commits. It's a known fact that China will "recruit" people to operate them. A quote: > They talk to them, say my friend, I see you like our special menu. Are you from China? Are you here on a VISA? Do you have family back there? Would you like your family to stay alive? Is your loyalty to this temporary employer or is your loyalty to…

I think we should seriously consider something like a ts clearance as mandatory for work on core technologies. Many other projects, both open and closed, are probably compromised by foreign agents.

Re: Backdoor in upstream xz/liblzma leading to SSH server compromise

#334

Jai Tan's commit history on his github profile suggests he took off for Christmas, new years, and spring break. I smell an American.

Sometimes you smell an American because someone wanted you to smell an American.

Operating on a target region schedule doesn't seem particularly sophisticated, at least compared to the all the efforts put into this exploit.

Re: Backdoor in upstream xz/liblzma leading to SSH server compromise

#336
post #303

Earlier quoted context omitted.

I think this has been in the making for almost a year. The whole ifunc infrastructure was added in June 2023 by Hans Jansen and Jia Tan. The initial patch is "authored by" Lasse Collin in the git metadata, but the code actually came from Hans Jansen: https://github.com/tukaani-project/xz/commit/ee44863ae88e377... > Thanks to Hans Jansen for the original patch. https://github.com/tukaani-project/xz/pull/53 There were…

1 week ago "Hans Jansen" user "hjansen" was created in debian and opened 8 PRs including the upgrade to 5.6.1 to xz-utils From https://salsa.debian.org/users/hjansen/activity Author: Hans Jansen - [Debian Games / empire]( https://salsa.debian.org/games-team/empire ): opened merge request "!2 New upstream version 1.17" - March 17, 2024 - [Debian Games / empire]( https://salsa.debian.org/games-team/empire ): opened mer…

That looks exactly like what you'd want to see to disguise the actual request you want, a number of pointless upstream updates in things that are mostly ignored, and then the one you want.

Re: Backdoor in upstream xz/liblzma leading to SSH server compromise

#337

I think its much more likely this was not a bad actor, given their long history of commits. It's a known fact that China will "recruit" people to operate them. A quote: > They talk to them, say my friend, I see you like our special menu. Are you from China? Are you here on a VISA? Do you have family back there? Would you like your family to stay alive? Is your loyalty to this temporary employer or is your loyalty to…

I think we should seriously consider something like a ts clearance as mandatory for work on core technologies. Many other projects, both open and closed, are probably compromised by foreign agents.

That's hard to do when the development of these libraries is so international. Not to mention that it's already so hard to find maintainers for some of these projects. Given that getting a TS clearance is such a long and difficult process, it would almost guarantee more difficulty in finding people to do this thankless job.

Re: Backdoor in upstream xz/liblzma leading to SSH server compromise

#338

I think its much more likely this was not a bad actor, given their long history of commits. It's a known fact that China will "recruit" people to operate them. A quote: > They talk to them, say my friend, I see you like our special menu. Are you from China? Are you here on a VISA? Do you have family back there? Would you like your family to stay alive? Is your loyalty to this temporary employer or is your loyalty to…

I think we should seriously consider something like a ts clearance as mandatory for work on core technologies. Many other projects, both open and closed, are probably compromised by foreign agents.

That just means the bad actors will all have clearance while putting in a bunch of hurdles for amateur contributors. The only answer is the hard one, constant improvement in methods to detect and mitigate bugs.

Re: Backdoor in upstream xz/liblzma leading to SSH server compromise

#339
Out of curiosity I looked at the list of followers of the account who committed the backdoor.

Randomly picked https://github.com/Neustradamus and looked at all their contributions.

Interestingly enough, they got Microsoft to upgrade ([0],[1]) `vcpkg` to liblzma 5.6.0 3 weeks ago.

[0] https://github.com/microsoft/vcpkg/issues/37197

[1] https://github.com/microsoft/vcpkg/pull/37199

Re: Backdoor in upstream xz/liblzma leading to SSH server compromise

#340
post #123

Earlier quoted context omitted.

I don't want to read too much into it, but the person (supposedly) submitting the PR seems to work at 1Password since December last year, as per his Linkedin. (And his Linkedin page has a link to the Github profile that made the PR).

As a 1Password user, I just got rather nervous.

Yubikeys starting to look kinda yummy.
Post reply on HN