Live data from Hacker News

The xz sshd backdoor rabbithole goes quite a bit deeper

twitter.com

81–90 of 310 posts

Re: The xz sshd backdoor rabbithole goes quite a bit deeper

#81
I'm concerned about the long game nature of things here. 1-Sure they bid their time to setup the "infrastructure" to create the backdoors. 2-I'm sure their plan was to play another long game after the exploit got in the wild, in production. It's the right way to spend lottery money. Invest. 3-That makes me wonder if such games are being played today.

Scary.

Re: The xz sshd backdoor rabbithole goes quite a bit deeper

#82
post #67
post #61

Earlier quoted context omitted.

Amusing. I was always irritated by the very concept of threadreaderapp and by people's propensity for posting the links (just read it on the website! There's no need to spend extra compute to join up some divs!) - but Elon's ever-increasing breakage of the site now makes it genuinely useful.

"ever increasing"? Twitter is completely, 110% unusable without an account (and dear god, I dare some of you to make a new account and see what the process and default content is. It's gross ). I say 110% not to be hyperbolic -- It shows you non-latest tweets on profiles, it doesn't let you see tweet threads or replies, even from the original poster when they post a chain of tweets. I literally can't read any of this…

I made an account after Musk took over and Mysterious Twitter X started mandating logging in, in large part since he made the place tolerable and I follow illustrators and official accounts for games I play anyway.

Making the account wasn't that annoying. Once upon a time they demanded my phone number and that was obnoxious to the point of noping out, but nowadays (after Musk took over?) they also take email instead. Email for registering accounts is nothing new, so no big deal; been doing that since 2002 when I registered my first forum account.

After I made my account I went and followed all the accounts I usually follow, and my recommendations got relevant in very short order: Posts from illustrators, the games, and players who play those games.

So, thanks Musk. You've at least convinced one guy to make an account where Dorsey flatly couldn't, and made the guy even happy about it which was pleasantly surprising.

Re: The xz sshd backdoor rabbithole goes quite a bit deeper

#84
post #82
post #67

Earlier quoted context omitted.

"ever increasing"? Twitter is completely, 110% unusable without an account (and dear god, I dare some of you to make a new account and see what the process and default content is. It's gross ). I say 110% not to be hyperbolic -- It shows you non-latest tweets on profiles, it doesn't let you see tweet threads or replies, even from the original poster when they post a chain of tweets. I literally can't read any of this…

I made an account after Musk took over and Mysterious Twitter X started mandating logging in, in large part since he made the place tolerable and I follow illustrators and official accounts for games I play anyway. Making the account wasn't that annoying. Once upon a time they demanded my phone number and that was obnoxious to the point of noping out, but nowadays (after Musk took over?) they also take email instead.…

>in large part since he made the place tolerable

oh yeah? Interesting you chose not to elaborate on how, given the statements I made about ruining public access stand.

But in summary, you're saying you used the platform the same way it was usable before Elon bought it, other than all of the things I mentioned that make it unusable for those not-logged-in? Let's be frank, Elon made it 200% worse, than relinquished to only 150% worse, and that's a win?

Re: The xz sshd backdoor rabbithole goes quite a bit deeper

#85
post #84
post #82

Earlier quoted context omitted.

I made an account after Musk took over and Mysterious Twitter X started mandating logging in, in large part since he made the place tolerable and I follow illustrators and official accounts for games I play anyway. Making the account wasn't that annoying. Once upon a time they demanded my phone number and that was obnoxious to the point of noping out, but nowadays (after Musk took over?) they also take email instead.…

>in large part since he made the place tolerable oh yeah? Interesting you chose not to elaborate on how, given the statements I made about ruining public access stand. But in summary, you're saying you used the platform the same way it was usable before Elon bought it, other than all of the things I mentioned that make it unusable for those not-logged-in? Let's be frank, Elon made it 200% worse, than relinquished to…

[flagged]

Re: The xz sshd backdoor rabbithole goes quite a bit deeper

#86
post #85
post #84

Earlier quoted context omitted.

>in large part since he made the place tolerable oh yeah? Interesting you chose not to elaborate on how, given the statements I made about ruining public access stand. But in summary, you're saying you used the platform the same way it was usable before Elon bought it, other than all of the things I mentioned that make it unusable for those not-logged-in? Let's be frank, Elon made it 200% worse, than relinquished to…

[flagged]

[deleted]

Re: The xz sshd backdoor rabbithole goes quite a bit deeper

#87
post #14

The weird thing about this one is how it seems super professional in some ways, and rather amateur in others. Professional in the sense of spending a long time building up an identity that seemed trustworthy enough to be made maintainer of an important package, of probably involving multiple people in social manipulation attacks, of not leaking the true identity and source of the attack, and the sophistication and ob…

Why do we assume the person building the trust is the attacker ?

Is not possible the attacker simply took over the account of some one genuinely getting involved in the community either hacked or just with $5 wrench and then committed the malicious code ?

Re: The xz sshd backdoor rabbithole goes quite a bit deeper

#88
post #14

The weird thing about this one is how it seems super professional in some ways, and rather amateur in others. Professional in the sense of spending a long time building up an identity that seemed trustworthy enough to be made maintainer of an important package, of probably involving multiple people in social manipulation attacks, of not leaking the true identity and source of the attack, and the sophistication and ob…

I read somewhere that some recent changes in systems would've made the backdoor useless so they had to rush out, which caused them to be reckless and get discovered

This refers to the fact that systemd was planning to drop the dependency on liblzma (the conpression library installed by xz), and instead dlopen it at runtime when needed. Not for security reasons, but to avoid pulling the libs into initramfs images.

The backdoor relies on sshd being patched to depend on libsystemd to call sd_notify(), which several distros had done.

OpenSSH has since merged a new patch upstream that implements similar logic to sd_notify() in sshd itself to allow distros to drop that patch.

So the attack surface of both sshd and libsystemd has since shrunk a bit.

Re: The xz sshd backdoor rabbithole goes quite a bit deeper

#89
post #14

The weird thing about this one is how it seems super professional in some ways, and rather amateur in others. Professional in the sense of spending a long time building up an identity that seemed trustworthy enough to be made maintainer of an important package, of probably involving multiple people in social manipulation attacks, of not leaking the true identity and source of the attack, and the sophistication and ob…

It’s also possible that this could be a change in personnel. Maybe the one who earned trust and took over was no more working for them. And an amateur took over with tight deadlines that lead to this gaffe for them.

The abrupt change in time-of-day when commits occurred supports the theory that Jai Tan is more than one person: https://twitter.com/birchb0y/status/1773871381890924872
Post reply on HN