Live data from Hacker News

The xz sshd backdoor rabbithole goes quite a bit deeper

twitter.com

61–70 of 310 posts

Re: The xz sshd backdoor rabbithole goes quite a bit deeper

#61

This. Could people stop posting xitter links and post threadreaderapp links like this instead. Thank you.

Amusing. I was always irritated by the very concept of threadreaderapp and by people's propensity for posting the links (just read it on the website! There's no need to spend extra compute to join up some divs!) - but Elon's ever-increasing breakage of the site now makes it genuinely useful.

Re: The xz sshd backdoor rabbithole goes quite a bit deeper

#62
post #7

The sophistication here is really interesting. And it all got caught because of a fairly obvious perf regression. It reminds of a quote I heard in one of those "real crime" shows: "There's a million ways to get caught for murder, and if you can think of half of them, you're a genius."

Maybe I’m just being naive or too trusting, but this is sort of what I think when folks are getting worried about other backdoors like this in the wild. Is it that they just got unlucky to get caught, or is this type of attack just too hard to pull off in practice? I’d like to think the later. But, we really don’t know.

They could have covered tracks better. So says Andres Freund, the person who discovered the backdoor: https://news.ycombinator.com/item?id=39923467

Re: The xz sshd backdoor rabbithole goes quite a bit deeper

#64
post #7

Earlier quoted context omitted.

Maybe I’m just being naive or too trusting, but this is sort of what I think when folks are getting worried about other backdoors like this in the wild. Is it that they just got unlucky to get caught, or is this type of attack just too hard to pull off in practice? I’d like to think the later. But, we really don’t know.

One measure might be that we never really found that many backdoors. Over time there is quite a large accumulation of hackers looking at the most mundane technical details. This may be confirmed by regular vulnerabilities that are found in sometimes many decades old software, since vulnerabilities are much harder to find than backdoors. For example shellshock was 30 year old code, PwnKit 12 and log4j was ~10 ish. So…

> Over time there is quite a large accumulation of hackers looking at the most mundane technical details.

Are there though? Even if true, there are probably enough places with very few eyes on them.

Re: The xz sshd backdoor rabbithole goes quite a bit deeper

#65
it's a rather good thing that this was found before it made it out broadly.

Not just for obvious reason of not wanting an unknown party to have RCE on your infrastructure. I think as people keep digging they will eventually formulate a payload which will allow the backdoor to be used by anyone.

As bad as it is for a single party to have access, it's much worse for any (every?) party to have access.

Re: The xz sshd backdoor rabbithole goes quite a bit deeper

#66

This. Could people stop posting xitter links and post threadreaderapp links like this instead. Thank you.

How do they get around the account/resource limits?

Web scraping is a cat-and-mouse game but all the cats got laid off.

Re: The xz sshd backdoor rabbithole goes quite a bit deeper

#67
post #61

This. Could people stop posting xitter links and post threadreaderapp links like this instead. Thank you.

Amusing. I was always irritated by the very concept of threadreaderapp and by people's propensity for posting the links (just read it on the website! There's no need to spend extra compute to join up some divs!) - but Elon's ever-increasing breakage of the site now makes it genuinely useful.

"ever increasing"? Twitter is completely, 110% unusable without an account (and dear god, I dare some of you to make a new account and see what the process and default content is. It's gross).

I say 110% not to be hyperbolic -- It shows you non-latest tweets on profiles, it doesn't let you see tweet threads or replies, even from the original poster when they post a chain of tweets. I literally can't read any of this content save for the threadreadapp link.

...

Re: The xz sshd backdoor rabbithole goes quite a bit deeper

#68

Earlier quoted context omitted.

Yet most murders go unsolved.

Depends on locale. In Germany something like 90% of murder cases are solved/cleared. In the U.S., I suspect a majority of the murders technically unsolved by police are cases where the identity of the perpetrators is somewhat of an open secret within communities that don't trust law enforcement (and LE similarly has little interest in working with them either.)

>In Germany something like 90% of murder cases are solved

You must watch out when reading the German crime statistics. "Solved" which is marked as "aufgeklärt" in those statistics just means that a suspect has been named. Not that someone actually did it/has been sentenced for the crime.

>https://de.wikipedia.org/wiki/Aufkl%C3%A4rungsquote#Deutschl... 2nd sentence

Re: The xz sshd backdoor rabbithole goes quite a bit deeper

#70
post #55
post #44

Earlier quoted context omitted.

Then most murderers are geniuses. Or most murder investigations are (by definition) incompetent. Or (more likely): The old idiom quoted above is stupid and useless. (That it presumes that murdering and getting away with it is somehow a noble or esteemed deed should be damning enough.)

Wrong. There’s no money or benefits in solving crimes. It could be done easily in many cases but nobody cares about certain people like gang members. Lots of cases where the murderer tells everyone but nobody cares.

Wrong?

Which part is wrong? Only 2/3 of these to choices can be wrong. The remaining one must be correct.

Post reply on HN