you are viewing a single comment's thread
view the rest of the comments
[–] 97 points 2 years ago (3 children)

Damn, it is actually scary that they managed to pull this off. The backdoor came from the second-largest contributor to xz too, not some random drive-by.

  • source
  • hideshow 6 child comments
  • [–] 51 points 2 years ago (1 child)

    They've been contributing to xz for two years, and commited various "test" binary files.

  • source
  • parent
  • hideshow 2 child comments
  • [–] 60 points 2 years ago (1 child)

    It's looking more like a long game to compromise an upstream.

  • source
  • parent
  • hideshow 2 child comments
  • [–] 18 points 2 years ago (1 child)

    Either that or the attacker was very good at choosing their puppet…

  • source
  • parent
  • hideshow 2 child comments
  • [–] 36 points 2 years ago (1 child)

    Well the account is focused on one particular project which makes sense if you expect to get burned at some point and don't want all your other exploits to be detected. It looks like there was a second sock puppet account involved in the original attack vector support code.

    We should certainly audit other projects for similar changes from other psudoanonymous accounts.

  • source
  • parent
  • hideshow 2 child comments
  • [–] 9 points 2 years ago (2 children)

    It would be nice if we could press formal charges

  • source
  • parent
  • hideshow 4 child comments
  • [+] -2 points 2 years ago* (last edited 1 year ago) (1 child)
  • [–] 14 points 2 years ago (3 children)

    Do you have a source for this?

  • source
  • parent
  • hideshow 6 child comments
  • [–] 2 points 2 years ago

    I don't have a source but I think it is safe to say given the large corporations and government institutions that rely on XZ utils. I'm sure Microsoft, Amazon, redhat ect are in talks with the federal government about this

  • source
  • parent