Earlier quoted context omitted.
Geez, this crowd. The clearest evidence that it was not an NSA attack is that it was not very good. It modified a CVS mirror. At no time was the source of truth (the bitkeeper repo) in any danger. Anybody that knew how this stuff worked at the time would have known it would be caught immediately. Not very state level expertise, pretty sad if it was the NSA.
> The clearest evidence that it was not an NSA attack is that it was not very good. I suspect you are being sarcastic, but in case you aren't, you may want to reexamine your assumptions. The colossal incompetence that is synonymous with government work doesn't magically stop at three-letter agencies. The FBI/CIA communication fuckups before 9/11 are just one famous example. The idea that the NSA is staffed with "uber…
The Linux backdoor attempt of 2003 (2013)
91–100 of 105 posts
Re: The Linux backdoor attempt of 2003 (2013)
#92Earlier quoted context omitted.
Ohh, that is clever - unless someone writes a test for these two new lines, and finds that they never return -EINVAL.
Did unit tests exist in 2003? I don't clearly remember when that idea came along, but comprehensive unit testing certainly was not standard practice 20 years ago... not in any organization I knew about at the time, anyway!
Edit: JUnit is from 1997. So the name was definitely in use in 2003. I attended a TDD tutorial before 2004 (don't remember the exact year). CI wasn't a thing yet, so you executed your unit tests manually. /edit
Do unit tests exist in the kernel today? There is some (or some would say a lot) of automatic testing for the kernel, but I don't remember seeing a single unit test.
Re: The Linux backdoor attempt of 2003 (2013)
#93I have the full story on that incident. It is actually really funny. If the guy who did it wants to come forward, that is his decision. [edit: I won't name names.] He did provided me the full story. He told me with the understanding that the story would go public, so I will dig it up and post it. I also interviewed the sysadmins who were running the box at the time. 1. it was not an NSA operation, it was done by a ha…
Geez, this crowd. The clearest evidence that it was not an NSA attack is that it was not very good. It modified a CVS mirror. At no time was the source of truth (the bitkeeper repo) in any danger. Anybody that knew how this stuff worked at the time would have known it would be caught immediately. Not very state level expertise, pretty sad if it was the NSA.
Re: The Linux backdoor attempt of 2003 (2013)
#94Earlier quoted context omitted.
OK, makes sense.. so the interviewed hacker mentioned that he got the code in by infiltrating the computer of "some developer"...
he was more specific, but I (a) don't remember the name off the top of my head, and (b) don't think it is beneficial to put them on blast. It isn't their fault they got hacked 20 years ago.
Re: The Linux backdoor attempt of 2003 (2013)
#95I have the full story on that incident. It is actually really funny. If the guy who did it wants to come forward, that is his decision. [edit: I won't name names.] He did provided me the full story. He told me with the understanding that the story would go public, so I will dig it up and post it. I also interviewed the sysadmins who were running the box at the time. 1. it was not an NSA operation, it was done by a ha…
He had many nicknames, but the one I knew him by was three characters long.
I lost contact with him sometime around 2004-2005, and I occasionally wonder what happened to him and if he's still alive.
I hope all is well.
Re: The Linux backdoor attempt of 2003 (2013)
#96Earlier quoted context omitted.
Wait was the guy you know the hacker or someone who discovered the hack by accident? If the latter, how do you know anything about the hacker's identity or motive?
the hacker. I interviewed the sysadmins about it.
Re: The Linux backdoor attempt of 2003 (2013)
#97I have the full story on that incident. It is actually really funny. If the guy who did it wants to come forward, that is his decision. [edit: I won't name names.] He did provided me the full story. He told me with the understanding that the story would go public, so I will dig it up and post it. I also interviewed the sysadmins who were running the box at the time. 1. it was not an NSA operation, it was done by a ha…
Geez, this crowd. The clearest evidence that it was not an NSA attack is that it was not very good. It modified a CVS mirror. At no time was the source of truth (the bitkeeper repo) in any danger. Anybody that knew how this stuff worked at the time would have known it would be caught immediately. Not very state level expertise, pretty sad if it was the NSA.
It's funny when you don't understand who you are replying to.
Re: The Linux backdoor attempt of 2003 (2013)
#98Earlier quoted context omitted.
Geez, this crowd. The clearest evidence that it was not an NSA attack is that it was not very good. It modified a CVS mirror. At no time was the source of truth (the bitkeeper repo) in any danger. Anybody that knew how this stuff worked at the time would have known it would be caught immediately. Not very state level expertise, pretty sad if it was the NSA.
> The clearest evidence that it was not an NSA attack is that it was not very good. I suspect you are being sarcastic, but in case you aren't, you may want to reexamine your assumptions. The colossal incompetence that is synonymous with government work doesn't magically stop at three-letter agencies. The FBI/CIA communication fuckups before 9/11 are just one famous example. The idea that the NSA is staffed with "uber…
Re: The Linux backdoor attempt of 2003 (2013)
#99Earlier quoted context omitted.
> The clearest evidence that it was not an NSA attack is that it was not very good. I suspect you are being sarcastic, but in case you aren't, you may want to reexamine your assumptions. The colossal incompetence that is synonymous with government work doesn't magically stop at three-letter agencies. The FBI/CIA communication fuckups before 9/11 are just one famous example. The idea that the NSA is staffed with "uber…
Iranian centrifuges would disagree with you as does the conversation about the apple exploit chain from last week.
See also all of the intelligence the US has provided about the Russian invasion into Ukraine. The US is really good at spy craft.
Re: The Linux backdoor attempt of 2003 (2013)
#100Earlier quoted context omitted.
Geez, this crowd. The clearest evidence that it was not an NSA attack is that it was not very good. It modified a CVS mirror. At no time was the source of truth (the bitkeeper repo) in any danger. Anybody that knew how this stuff worked at the time would have known it would be caught immediately. Not very state level expertise, pretty sad if it was the NSA.
> The clearest evidence that it was not an NSA attack is that it was not very good. I suspect you are being sarcastic, but in case you aren't, you may want to reexamine your assumptions. The colossal incompetence that is synonymous with government work doesn't magically stop at three-letter agencies. The FBI/CIA communication fuckups before 9/11 are just one famous example. The idea that the NSA is staffed with "uber…
That’s really all you need dude. And yet both private and public sector intelligence jobs are selective. Supply and demand might help you reconcile your other points.
You slightly underestimate the pool of extremely patriotic or nationalistic smart engineers and scientists around.
If your basic thesis was correct no video games would get made either. Most of them could go get that FAANG money for arguably better work life balance. People have more motivations than you realize. And the idea that all the smartest engineers and scientists exclusively work for FAANG is a contrivance only believed on this dumb site. (The equally idiotic corollary is that all the smartest people work in software).
I also think you are underestimating the lifetime earning potential of top intelligence workers. 9 to 5 government jobs don’t have to be forever.
Finally, the sophistication of state level attacks such as in Iran is clear. The evidence exists, and you are wrong.
And you’re missing the point, it isn’t even that this attack wasn’t sophisticated it was that clearly no one sat down for even a few minutes to discuss how it would be detected. An organization, even a private hacking group, would have discussed this.