Live data from Hacker News

XZ Backdoor: Times, damned times, and scams

rheaeve.substack.com

71–80 of 193 posts

Re: XZ Backdoor: Times, damned times, and scams

#71
post #63
post #54

Earlier quoted context omitted.

Not sure why you’re downvoted. When you think of state actors, Israel comes very high (stuxnet etc), as well as the usual US/Russia/China/NK groups. Unit 8200 in the IDF especially have a very notable reputation. That’s not to say other counties don’t have capabilities (and this doesn’t look like you need the resources of a group like say the NSA or GCHQ for this particular attack - indeed it could just be a single l…

If the only think I knew was UTC+2 (and I don't even think I know that, I'm really cautious with assumptions about what mistakes that kind of people plausibly make), Israel would be very high on the list. But FWIW, 25Dec is a Catholic holiday, and even though it's mentioned on Wikipedia page about Israel holidays, I'm not sure how official that is. I mean, it doesn't seems to be, like, a real Israeli holiday.

I think no commits on December 25 is not enough to go by. He's been active for about 2 years, so that's what, 1-2 Christmases? I assume he doesn't commit literally every day. So it could be a coincidence that he didn't on those particular 1-2 days. Also, in many Orthodox Christian majority countries including those in UTC+2 they don't celebrate on 12/25.

But doesn't Israel also not follow a typical work week? Eg. No commits on Friday afternoon?

Re: XZ Backdoor: Times, damned times, and scams

#72
post #9

Earlier quoted context omitted.

This article asserts some opsec failures - time zones switching when they shouldn’t etc. It’s quite plausible that they didn’t manage perfect vpn usage every single time.

Expert level opsec - very rarely make deliberate "mistakes" by having an inconsistent timezone, or tunneling through someone's compromised home device instead of a VPN, to throw adversaries on wild goose chases.

They also committed with a different email address and a different name once or twice. This may have been intentional, though, to misdirect.

Re: XZ Backdoor: Times, damned times, and scams

#75
post #32

I don't think he was from Eastern Europe, but if you want to look at UTC+0200/+0300, in Europe this only includes Finland, Baltics, Ukraine, Romania, Moldavia, and Greece. But notably if you look a bit down it also includes a good chunk of the Middle East, including Israel.

What about the daylight savings time and holidays points? How do they line up for Israel?

I don't know about holidays but Israel uses the same daylight savings as the mentioned Eastern Europe countries, ie switching from UTC+0200 to +0300 at around the same time - only difference is that they start daylight savings on Friday instead of Sunday the same week.

Re: XZ Backdoor: Times, damned times, and scams

#76
post #57

Poor Jia. Two whole years of work down the drain. If you're reading this Jia, remember that you miss 100% of the shots you don't take. Chin up, brother.

Don't worry, they (it's a team) also contribute to image libraries, webkit, Kubernetes, ...

Yes, unironically, that, being a huge leak, really convinces me that we all have multiple RCEs on each of our systems. I mean, we already kinda knew that, of course, but even now that I'm typing this it's a bit hard for me to actually believe it. But realistically I think it's pretty much a proven fact. This level of sophistication… what did I even expect? Of course well-payed teams of high-level professionals are working in this area for a very long time by now. This is basically like professional football players competing against office workers in their late thirties who like to kick a ball on weekends. I am comforting myself by thinking that something a bit more high-level, written in python or even golang, or, oh hell, maybe even rust would be more a bit more transparent for other contributors… but even this is probably a lie. And if it wouldn't be, surely tons of super-popular low-level packages written in C/C++ are as good as incomprehensible for somebody who isn't specifically security-auditing this.

Re: XZ Backdoor: Times, damned times, and scams

#77
If some nation state actor dis this, I imagine they couldve easily modified times of their commits, takin into consideration holidaya and such. Also, nation state actors have tons of resources. They could have people waiting to make commits or schedule it with something like cron.

Re: XZ Backdoor: Times, damned times, and scams

#78
post #45

Earlier quoted context omitted.

Most (but not all ) VPN providers keep logs and payment info that are subpoenable. You could use something like Mulvad with Lightning Network payments, but I am not sure that even that is fully anonymous. The Witopia VPN that he used for IRC [1] is US based: https://www.personalvpn.com/contact-us/ and they don't mention neither LN payments nor not keeping logs. 1. "~jiatan@185.128.24.163" https://boehs.org/node/every…

Mullvad accepts cash in an envelope with no return address, good luck tracing that

Postal mail has non-zero metadata, e.g. origin can be traced at least to departure postal code.

Re: XZ Backdoor: Times, damned times, and scams

#79
post #47
post #16

Earlier quoted context omitted.

If you’ve missed probably the largest cyber security story since stuxnet, and arguably bigger than that, I suggest you start looking at the last few days. Start here. https://news.ycombinator.com/item?id=39865810

> arguably bigger than that That’s a stretch. Stuxnet was the first acknowledged state cyber attack, utilized multiple zero days, and destroyed nuclear weapons manufacturing facilities. Bigger in scope sure, but bigger unconditionally? I don’t know about that.

Depends on the set of global resources, including development, CI/CD and production systems, reachable by compromised sshd.
Post reply on HN