Live data from Hacker News

Backdoor in upstream xz/liblzma leading to SSH server compromise

openwall.com

951–960 of 1001 posts

Re: Backdoor in upstream xz/liblzma leading to SSH server compromise

#952

Unfortunately, this is how good bad actors work: with a very long-term point of view. There is no “harmless” project any more.

(I detached this subthread from https://news.ycombinator.com/item?id=39866275, for the sake of pruning the top heavy thread.)

Re: Backdoor in upstream xz/liblzma leading to SSH server compromise

#953
post #821

Earlier quoted context omitted.

I think this has been in the making for almost a year. The whole ifunc infrastructure was added in June 2023 by Hans Jansen and Jia Tan. The initial patch is "authored by" Lasse Collin in the git metadata, but the code actually came from Hans Jansen: https://github.com/tukaani-project/xz/commit/ee44863ae88e377... > Thanks to Hans Jansen for the original patch. https://github.com/tukaani-project/xz/pull/53 There were…

Does anybody know anything about Jia Tan? Is it likely just a made up persona? Or is this a well-known person.

It’s certainly a pseudonym just like all the other personas we’ve seen popping up on the mailing list supporting this “Jia Tan” in these couple of years. For all intents and purposes they can be of any nationality until we know more.

Re: Backdoor in upstream xz/liblzma leading to SSH server compromise

#955

For someone who does not understand the packages used, could you please summarize in layman non technical terms. Thanks I did read the main post.

This link helped a little. https://gist.github.com/thesamesam/223949d5a074ebc3dce9ee78b...

Re: Backdoor in upstream xz/liblzma leading to SSH server compromise

#957

For someone who does not understand the packages used, could you please summarize in layman non technical terms. Thanks I did read the main post.

This link helped a little. https://gist.github.com/thesamesam/223949d5a074ebc3dce9ee78b...

i added there something about a possible planned kernel attack which not mentioned so much yet.

https://gist.github.com/thesamesam/223949d5a074ebc3dce9ee78b...

Re: Backdoor in upstream xz/liblzma leading to SSH server compromise

#958
post #146

Yikes! Do you have any info on the individual's background or possible motivations?

There is zero web presence for this person and associated email address. Looks more likely a fake identity than compromised account.

I am more interest about his git commits https://github.com/JiaT75?tab=overview&from=2021-12-01&to=20... If JiaT75 is a Chinese, then his working log should follow Chinese Holiday, especially Spring Festival and National Holiday. Chinese usually not work on first 3 days of Spring Festival and National Holiday - 2021 2/11 - 2/13 (few commits), 2021 10/1 - 10/3 (nothing) 2022 1/31 - 2/2 (huge commits on 1/31, suspect), 2022 10/1 - 10/3 (nothing) 2023 and 2024, not very much commits. So 2022 1/31 huge commits is a proof that he is not follow Chinese holiday.

But wait, 2021 is his active year, but he missed almost all Aug. Is he on holiday? Who can have such a long holiday? What i can think is a solider who has a long vacation (探亲假). So let's guess he is a solider then it's sense that he worked on Spring Holiday because they need on duty. Let's double check again, if he is a solider, then they will have a holiday on every Aug. 1 because it's liberation army day. I check and no commits on all 4 years Aug. 1.

Re: Backdoor in upstream xz/liblzma leading to SSH server compromise

#959
Also the attacker included in the 5.6.0 release the support for the long-awaited multi-threading decompression (and - broken - sandbox) making it very attractive to upgrade to...

It was probably a tactic to give a reason to upgrade. It's not always a fault for those who did or tried to do.

Post reply on HN