A stealth attack came close to compromising the Internet
economist.com
economist.com
The article quotes someone pooh-poohing "hobbyist" maintainers. But just because something is your hobby doesn't mean you're not a professional at it. Just because you don't get paid for it doesn't mean it's not an incredibly valuable part of your contribution to the good of your neighbors. Keep up the excellent work, everyone.
I hope the xz lesson is one that moves us toward the ideal of open source, not away from it.
And just like everyone else, these have been compromised before.
Oh and it appears the dev was working via email rather than the mailing list for a bit too. Probably should be more suspicious of any back channel attempts like that too.
Precisely, I truly do not understand how these people witness a potentially catastrophic event of such proportions and instead of asking "dear God, I wonder how many backdoors there are in the Windows operating system that we don't know and will never find out about!?! Thankfully Linux and its ecosystem can be somewhat audited!". Instead they go full blown "please make it go away, if it's visible by us it means it's terrible and dangerous! FOSS is insecure!"
I've said it once[1] and I'll say it again: FOSS delivered both on its pitfalls and its strengths.
Moreover, and I'll never get tired of repeating this:
Although this might be indeed a FOSS-exclusive or FOSS-adjacent kind of risk that ultimately materialized, as some would like to call it, it’s nevertheless also an issue where checks and balances that are only intrinsically possible in FOSS worked as expected and needed. Yes, there was an element of luck in the discovery of CVE-20240-3094, but it is undeniable source code availability and other FOSS customs tipped the scale in the community’s favor.
[1] https://jdsalaro.com/note/xz-liblzma-linux-backdoor-foss-pit...
If something like this happened in windows, it could be found in the same way, and the culprit could be identified and charged with crimes.
Just take the L for FOSS instead of trying a UNO reverse card
Where was it? The explanation I saw included obsfucated code. ?
in some sense, exact specifics of the attack were discovered because norm of open source is even more open than the gpl-and-co require
The backdoor consisted of a combination of publicly visible code and binary blob test files available in the project's repository as well as obfuscated build scripts which were contained only in the released tarballs, tucked away, which, nevertheless, were also publicly accessible, decompressable and auditable[1]
The cynicist in me fears this is how a large part of politics operates:
A lingering problem that is highly visible is bad: Then the public is expecting you to find a solution, and if you don't, it will reflect negatively on your public image, chances of reelection, etc.
In contrast, a massive crisis or catastrophe that occurs (seemingly) out of nowhere is actually good (as long as you aren't affected yourself), because it allows you to appear as the hero, rally people behind a common cause, access a massive amount of additional resources and funding, push through bills for completely unrelated political goals as long as you can somehow relate them to the catastrophe, etc.
This means there is a massive political incentive to push problems under the rug: As long as no one knows the problem is there, all is fine - and if the problem should unexpectedly blow up, that's fine too, because then there will be a "crisis" that you can politically benefit from.
The visible bugs get fixed. Invisible ones get used and exploited.
https://www.defenseone.com/ideas/2024/04/how-fix-militarys-s...
When it appears in diverse multiple places simultaneously, I generally believe someone is coordinating a media campaign. You may think that's paranoid but look at the merits of the argument: how else is it explained? They didn't coincidentally think of the exact same argument, especially when FOSS's reputation has been well-established for a long time - why now, for this particiular vulnerability, are all these people suddenly expressing doubts? And they didn't read each other's articles: these articles need to be thought of, written, edited, and published.
You (those reading on HN) needs to push back and point out the absurdity of the argument now. Otherwise, even if it doesn't cause major changes, it will plant a seed - FUD, using the old IBM technique. Next time there's a incident, they will just keep beating that drum, as for-profit companies make another reach for more power. I'm sure others here will point out plenty of flaws in the argument; biggest of all is that proprietary software has the same problems - you can list them with ease.
Who is behind it? We may know when the first one says they are discontinuing using FOSS.
EDIT: Another reason to think it's coordinated: It's absolute BS. Nobody in IT would seriously make this claim. Everyone uses FOSS one way or another, and everyone has seen plenty of awful proprietary software. It's a deception intended for the uninformed outside IT.
Think about it: Many people saying the truth simultaneously makes sense. But for many people to come up with the same BS - and any IT professional is deceiving people knowingly - that takes coordination.
You don't need centralized coordination. Companies that sell closed-source software are inherently incentivized to defend their practices and denigrate their competitors. It's not a cabal, it's the systematic perverse incentives created by financial interests.
I do think for the defense and a lot of other industries it would be good for them to buy OSS code through a third-party that actually vetted the versions for bugs and other issues. Like the alternative is each of the defense companies expecting each of their developers to vet each library which is just a colossal wasted of work.
Without being pedantic, what do you think of my counterargument to that point in the GP? (No complaint if you missed it, but let's start from there.)
This counterargument?
I think my comment still applies. One of them had an original thought and the other copied them.
However, on further research I think at least with this article you are correct. The guy works for Chainguard [1] so he has a financial interest in the Iron Bank no longer existing.
The guys previous article for Log4J [1] is arguing for public funds to be spent auditing OSS. And given his current work I don't think he's against FOSS; just as long as you get the FOSS through him.
[1]: https://www.chainguard.dev/
[2]: https://www.defenseone.com/ideas/2022/08/military-should-red...
While I do understand how you use that word here, it literally does, and it does in the general case because of incentives. (Thankfully, exceptional people that rise above this do exist, but hopefully we'll find a way to do better than basically using martyrs.)
If the original maintainer can work with LEOs, “jia tan” may have left some clues in the “off list” communications. Maybe headers off original emails show a pattern.
Maybe even coordinate with Google since the attackers used Gmail accounts. Quite possible an attacker accidentally logged in from a non-sanctioned device or sent email from non state owned device.
We are human after all and can make mistakes. Just as the attacker(s) got clumsy towards the end due to patching out loading of unnecessary libraries in systemd
I do wonder when they’ll settle on a likely culprit. A few hours ahead of GMT and doesn’t work on Eastern European holidays? There’s probably more work to be done, but just going by the commit history, surely there’s a way to make a more granular assumption, because not all of those countries share all of the same holidays…
A couple years ago I was talking to someone who came of age since 2016, when I think many of these changes began moving rapidly. When I said something about a community project, they ridiculed the idea that people could and would come together and do good, productive things. I used FOSS as an example, and also of course, democracy.
The lack of social trust is a well-known concept, but I don't know if people see the massive change where instead of defaulting to trust, the default is paranoia and also being distrustful - scamming others ('animal spirits', as Jamie Dimon calls them). It's also ridiculing, like my friend, the idea of democracy - for example, the popular notion that doing anything to stand up to power, especially organized protests, is pointless. The briefest glance at history shows otherwise, but of course fact & reason are not the mode of analysis these days. Cui bono? People who have capital and power; people who want to take down the power of the people and democracy.
If you look at FOSS from the usual humanistic democratic perspective, with social trust (which is part of human nature, despite attempts to destroy it) - that free people generally do good and well and can self-organize, and that now the Internet provides a way for them to do all that easily - then these big coordinated FOSS projects are a happy thing and make sense.
But if you look at it from the current madness, the paranoia and hate, then FOSS becomes suspect. Without social trust, how could such an organization work? Only an organization controlled by a powerful person could acheives something. Think about it: why is the latter type of organization more likely to work than the former?
Calling him a 'nerd' is somewhat dismissive and disrespectful. Call him what he is - a professional.
You must have missed that in the 2010s being a nerd became cool. It's not a derogatory term with the younger generations, it's a term of endearment and respect, an identity that is owned and aspired to.
The nerds were now in their 20s and 30s, so when the 50s and 60s geezers called them nerds as always the response was "Yeah. I'm a nerd and I'm making money while you're slated for retirement. Problem?" and the term became an identity for those generations.
Whatever we're calling the Z-ers today, they will do to us what we did to those who called us nerds.
What I'm seeing is that starting in the mid-2010s the number of high schoolers who identify as nerds has gone up dramatically, to the point where from what I've observed even the popular kids who end up surrounded with their own gang are about as likely to call themselves a nerd and engage in stereotypical nerdy activities as they are to be the football players.
Granted, that impression is probably on its way out with how much reputation/"cool factor" the tech industry is losing in recent years.
You need only consider the mental images that come up when you consider a 'nerd' vs. a craftsman or an artisan. This man is an artisan.
'Nerd' is used by technically-inclined people in that age group as a term of endearment—it indicates that you're part of their tribe, that they recognize you as one of their own. You can take offense at that because it's not how you think of the word, but that's the way the language has gone.
> I was doing some micro-benchmarking at the time, needed to quiesce the system to reduce noise. Saw sshd processes were using a surprising amount of CPU, despite immediately failing because of wrong usernames etc. Profiled sshd, showing lots of cpu time in liblzma, with perf unable to attribute it to a symbol. Got suspicious.
from: https://mastodon.social/@AndresFreundTec/112180406142695845
Not that they would ever agreee to any kind of shared support for the free s/w projects that today's internet depends on, because... Elon needs more.
Also, I would argue, a good reasson not to be an update apostle.
Disable automatic updates, update when you need an updated version of something, or a new vuln directly affects your usage model, not just because an update is available...
> ... Other fixes are regulatory. America’s cyber strategy, published last year, makes clear that the responsibility for failures should lie not with open-source developers but “the stakeholders most capable of taking action to prevent bad outcomes”. In practice that means governments and tech giants, both of which benefit enormously from free software libraries. Both should expand funding for and co-operation with non-profit institutions, like the Open Source Initiative and the Linux Foundation, which support the open-source ecosystem. The New Responsibility Foundation, a German think-tank, suggests that governments might, for example, allow employees to contribute to open-source software in their spare time and ease laws that criminalise “white hat” or ethical hacking.