A podcast about the xz backdoor with the guy who found it
risky.biz
risky.biz
It just slays me that Andres Freund, absolute bastion of database goodness, is now just "the guy who found the xz bug". Funny old world.
Patrick Gray is a good interviewer and news source but he is also a big booster of the American surveillance apparatus, and has spoken against such reasonable reforms as requiring the the FBI get a bloody warrant when it searches for Americans data in the 702 database (data that is collected specifically for foreign intel purposes and thus subject to less constitutional scrutiny). He recently defended the NSA's acquisition of netflow data because the NSA needs it to do its work. as if constitutional privacy rights should give way to a spy agencies priorities.
He is just way to trusting of these agencies abilities to police themselves. I swear his quote when they talked about nsa getting netflow data was something along the lines of "if people only knew how many meetings they had to have before they would understand". Those are both examples I am pulling from memory so don't take them as gospel. And of course, no source of news / commentary is unbiased.
I listen to and enjoy the risky buiz podcast. And institutional trust is a legitimate aspect of security, especially in infosec. I just wish he was more skeptical of western law enforcement and intelligence agencies (he is already more then skeptical of non-western law enforcement and intelligence agencies, which is fine, I just wish he did not give the five eyes countries a pass because we are "the good guys"). He recently interviewed people at NSA headquarters for petes sake.
I wonder if a subsequent, more sophisticated attack could add some bogus debugging symbols to better hide its track.
Andres Freund starts speaking at 5:09.
I'm not affiliated with the podcast. I only did a very cursory review of the S2T results, so expect mistakes.
- A serious SSH backdoor was discovered in the xz Linux compression library, allowing attackers to compromise SSH servers.
- The backdoor was discovered by Andres Freund, a Postgres developer, who noticed suspicious CPU usage and login attempts on his systems.
- The xz backdoor allowed attackers to bypass authentication and gain root access on compromised systems.
- Microsoft faced significant criticism from the CSRB (Cybersecurity Review Board) for a cascade of errors related to a China-based hack.
- Ukraine was able to leverage an old WinRAR vulnerability to hack into Russian systems as part of the ongoing conflict.
- There have been recent "MFA bombing" attacks targeting Apple users, combining push notifications and social engineering.
- A ransomware gang leaked stolen Scottish healthcare patient data as part of an extortion attempt.
- Renowned security expert and author Ross Anderson passed away.
- The episode features a discussion with Andres Freund about his discovery of the xz backdoor.
- The podcast sponsor, Island, discusses how enterprises are moving away from VDI (Virtual Desktop Infrastructure) towards security-focused enterprise browsers.
2024-02-29: On GitHub, @teknoraver sends pull request to stop linking liblzma into libsystemd. It appears that this would have defeated the attack. Kevin Beaumont speculates that knowing this was on the way may have accelerated the attacker’s schedule. @teknoraver commented on HN that the liblzma PR was one in a series of dependency slimming changes for libsystemd; there were two mentions of it in late January.
I think that this is a plausible explanation for a rushed schedule and an actually justified deadline.
There's nothing arbitrary about the deadlines, the clock was absolutely ticking.
Not James bond stuff, no beautiful high value targets getting seduced, its just some guy with ADD that spent about 15 days too many bike shedding and botched a critical deadline.
But yeah, likely there are many undiscovered critical bugs waiting to be found and maybe also more intentional backdoors.
not challenging you. Genuinely curious.
If you were referring to the malicious code being contributed, not to the open source project as a whole, I don't think "completely visible" is an accurate description of the deliberately obfuscated chain of m4 gobbledygook and binary blobs that makes up the backdoor.