Live data from Hacker News

The Linux backdoor attempt of 2003 (2013)

freedom-to-tinker.com

91–100 of 105 posts

Re: The Linux backdoor attempt of 2003 (2013)

#91
post #85
post #79

Earlier quoted context omitted.

Geez, this crowd. The clearest evidence that it was not an NSA attack is that it was not very good. It modified a CVS mirror. At no time was the source of truth (the bitkeeper repo) in any danger. Anybody that knew how this stuff worked at the time would have known it would be caught immediately. Not very state level expertise, pretty sad if it was the NSA.

> The clearest evidence that it was not an NSA attack is that it was not very good. I suspect you are being sarcastic, but in case you aren't, you may want to reexamine your assumptions. The colossal incompetence that is synonymous with government work doesn't magically stop at three-letter agencies. The FBI/CIA communication fuckups before 9/11 are just one famous example. The idea that the NSA is staffed with "uber…

Iranian centrifuges would disagree with you as does the conversation about the apple exploit chain from last week.

Re: The Linux backdoor attempt of 2003 (2013)

#92

Earlier quoted context omitted.

Ohh, that is clever - unless someone writes a test for these two new lines, and finds that they never return -EINVAL.

Did unit tests exist in 2003? I don't clearly remember when that idea came along, but comprehensive unit testing certainly was not standard practice 20 years ago... not in any organization I knew about at the time, anyway!

I believe unit tests existed. I had a test training in 2000 and things were pretty systematic already then. Not 100% sure whether the exact term was used then.

Edit: JUnit is from 1997. So the name was definitely in use in 2003. I attended a TDD tutorial before 2004 (don't remember the exact year). CI wasn't a thing yet, so you executed your unit tests manually. /edit

Do unit tests exist in the kernel today? There is some (or some would say a lot) of automatic testing for the kernel, but I don't remember seeing a single unit test.

Re: The Linux backdoor attempt of 2003 (2013)

#93
post #79
post #3

I have the full story on that incident. It is actually really funny. If the guy who did it wants to come forward, that is his decision. [edit: I won't name names.] He did provided me the full story. He told me with the understanding that the story would go public, so I will dig it up and post it. I also interviewed the sysadmins who were running the box at the time. 1. it was not an NSA operation, it was done by a ha…

Geez, this crowd. The clearest evidence that it was not an NSA attack is that it was not very good. It modified a CVS mirror. At no time was the source of truth (the bitkeeper repo) in any danger. Anybody that knew how this stuff worked at the time would have known it would be caught immediately. Not very state level expertise, pretty sad if it was the NSA.

I think you give the government a lot more credibility than deserved...

Re: The Linux backdoor attempt of 2003 (2013)

#94
post #31

Earlier quoted context omitted.

OK, makes sense.. so the interviewed hacker mentioned that he got the code in by infiltrating the computer of "some developer"...

he was more specific, but I (a) don't remember the name off the top of my head, and (b) don't think it is beneficial to put them on blast. It isn't their fault they got hacked 20 years ago.

So it is the developer, not the perpetrator?

Re: The Linux backdoor attempt of 2003 (2013)

#95
post #3

I have the full story on that incident. It is actually really funny. If the guy who did it wants to come forward, that is his decision. [edit: I won't name names.] He did provided me the full story. He told me with the understanding that the story would go public, so I will dig it up and post it. I also interviewed the sysadmins who were running the box at the time. 1. it was not an NSA operation, it was done by a ha…

I remember the guy who did it from IRCnet #hax.

He had many nicknames, but the one I knew him by was three characters long.

I lost contact with him sometime around 2004-2005, and I occasionally wonder what happened to him and if he's still alive.

I hope all is well.

Re: The Linux backdoor attempt of 2003 (2013)

#96
post #26
post #7

Earlier quoted context omitted.

Wait was the guy you know the hacker or someone who discovered the hack by accident? If the latter, how do you know anything about the hacker's identity or motive?

the hacker. I interviewed the sysadmins about it.

What is this a psi-op? This has been deeply frustrating to parse. You don't make sense.

Re: The Linux backdoor attempt of 2003 (2013)

#97
post #79
post #3

I have the full story on that incident. It is actually really funny. If the guy who did it wants to come forward, that is his decision. [edit: I won't name names.] He did provided me the full story. He told me with the understanding that the story would go public, so I will dig it up and post it. I also interviewed the sysadmins who were running the box at the time. 1. it was not an NSA operation, it was done by a ha…

Geez, this crowd. The clearest evidence that it was not an NSA attack is that it was not very good. It modified a CVS mirror. At no time was the source of truth (the bitkeeper repo) in any danger. Anybody that knew how this stuff worked at the time would have known it would be caught immediately. Not very state level expertise, pretty sad if it was the NSA.

I'd trust grugq over you any day of the week, lol.

It's funny when you don't understand who you are replying to.

Re: The Linux backdoor attempt of 2003 (2013)

#98
post #85
post #79

Earlier quoted context omitted.

Geez, this crowd. The clearest evidence that it was not an NSA attack is that it was not very good. It modified a CVS mirror. At no time was the source of truth (the bitkeeper repo) in any danger. Anybody that knew how this stuff worked at the time would have known it would be caught immediately. Not very state level expertise, pretty sad if it was the NSA.

> The clearest evidence that it was not an NSA attack is that it was not very good. I suspect you are being sarcastic, but in case you aren't, you may want to reexamine your assumptions. The colossal incompetence that is synonymous with government work doesn't magically stop at three-letter agencies. The FBI/CIA communication fuckups before 9/11 are just one famous example. The idea that the NSA is staffed with "uber…

FAANG money is a relatively recent thing. Stock options used to be the only way you might make millions as a developer, at that was always a gamble. The NSA probably has a lot of seasoned developers who started their careers when the pay gap was much smaller.

Re: The Linux backdoor attempt of 2003 (2013)

#99
post #85

Earlier quoted context omitted.

> The clearest evidence that it was not an NSA attack is that it was not very good. I suspect you are being sarcastic, but in case you aren't, you may want to reexamine your assumptions. The colossal incompetence that is synonymous with government work doesn't magically stop at three-letter agencies. The FBI/CIA communication fuckups before 9/11 are just one famous example. The idea that the NSA is staffed with "uber…

Iranian centrifuges would disagree with you as does the conversation about the apple exploit chain from last week.

Those two were my wake up calls. The US absolutely is in the hacking business, but they are not in the getting caught business. Everything we have seen so far is incredibly sophisticated and took years to discover. How can you then go out and claim that the NSA isn’t incredibly competent?

See also all of the intelligence the US has provided about the Russian invasion into Ukraine. The US is really good at spy craft.

Re: The Linux backdoor attempt of 2003 (2013)

#100
post #85
post #79

Earlier quoted context omitted.

Geez, this crowd. The clearest evidence that it was not an NSA attack is that it was not very good. It modified a CVS mirror. At no time was the source of truth (the bitkeeper repo) in any danger. Anybody that knew how this stuff worked at the time would have known it would be caught immediately. Not very state level expertise, pretty sad if it was the NSA.

> The clearest evidence that it was not an NSA attack is that it was not very good. I suspect you are being sarcastic, but in case you aren't, you may want to reexamine your assumptions. The colossal incompetence that is synonymous with government work doesn't magically stop at three-letter agencies. The FBI/CIA communication fuckups before 9/11 are just one famous example. The idea that the NSA is staffed with "uber…

> I'm sure there are a select few who find this appealing

That’s really all you need dude. And yet both private and public sector intelligence jobs are selective. Supply and demand might help you reconcile your other points.

You slightly underestimate the pool of extremely patriotic or nationalistic smart engineers and scientists around.

If your basic thesis was correct no video games would get made either. Most of them could go get that FAANG money for arguably better work life balance. People have more motivations than you realize. And the idea that all the smartest engineers and scientists exclusively work for FAANG is a contrivance only believed on this dumb site. (The equally idiotic corollary is that all the smartest people work in software).

I also think you are underestimating the lifetime earning potential of top intelligence workers. 9 to 5 government jobs don’t have to be forever.

Finally, the sophistication of state level attacks such as in Iran is clear. The evidence exists, and you are wrong.

And you’re missing the point, it isn’t even that this attack wasn’t sophisticated it was that clearly no one sat down for even a few minutes to discuss how it would be detected. An organization, even a private hacking group, would have discussed this.

Post reply on HN