19 ms·
I see it this way (being a Russian): it's not a copyright claim issue, but rather a hostage situation with bandits involved (a.k.a Russian authorities), and wha
by ivan4th 7y ago
I see it this way (being a Russian): it's not a copyright claim issue, but rather a hostage situation with bandits involved (a.k.a Russian authorities), and what they want is ransom so that top #1-2 nginx contributors don't go to jail for some 10 years.
- auiya 7y agoIt feels like an intelligence shakedown. Nginx has a rather large install base. FSB would love to have an entry point in it I'm sure, or maybe they previously had one and are trying to gain it back?
- anonymousjunior 7y agoThis is what's really concerning. If FSB was able to actually implement something and shell all nginx boxes (and thusly obtain SSL certs, intercept communications, etc..) imagine how much access they'd have.
- account73466 7y agoThen they would definitely advertise it by attacking the company so that the whole world would know about their secret backdoor. Very smart, indeed!
- true_religion 7y agoJust thinking about it would have a chilling effect which to the authorities may be better than actual access.
- Filligree 7y agoI'm going to switch from nginx to Caddy, so I guess?
- kick 7y agoPhysical access is easier to get than remote access when you have a baton and the intelligence of a cop.
- dsl 7y agoFSB/GRU are more than just thugs with batons, they are professionals who could easily slip in to a building at night and access computers without anyone knowing. Basically the Russian CIA.
- golergka 7y agoGRU have been severely embarrassed quite a few times in the last few years. It does seem that they're much closer to thugs with batons.
- penagwin 7y agoOn the flip side I feel like nginx has too high of a profile. It'd be better to target some other low level system package or npm/pip module, etc.
- stjohnswarts 7y agothat's not going to happen, too many security experts constantly monitoring nginx. That's the beauty of it being a high profile open source project.
- auiya 7y agoYeah? https://en.wikipedia.org/wiki/Kleptography https://en.wikipedia.org/wiki/Kleptography https://en.wikipedia.org/wiki/Heartbleed https://en.wikipedia.org/wiki/Heartbleed https://en.wikipedia.org/wiki/Shellshock_%28software_bug%29 https://en.wikipedia.org/wiki/Shellshock_%28software_bug%29 https://www.computerweekly.com/news/252473363/EU-patches-20-year-old-open-source-vulnerability https://www.computerweekly.com/news/252473363/EU-patches-20-... https://en.wikipedia.org/wiki/Dual_EC_DRBG https://en.wikipedia.org/wiki/Dual_EC_DRBG
- TheRealDunkirk 7y ago"I keep track of these things, Clark. One of us has to."
- oefrha 7y agoJust like too many security experts monitoring crypto standards so NIST wouldn’t try to slip in a backdoor?
- lawnchair_larry 7y agoNo, not similar. Crypto is very different.
- account73466 7y agoor maybe or maybe ...
- kiney 7y agonginx is open source. I tend to use the distribution provided packages which in case of debian are reproducible builds. (yeah, i know there's a pro version of nginx. never used it)
- iforgotpassword 7y ago"It's open source, someone surely is doing regular thorough security audits."
- stjohnswarts 7y agoAuditing one of the world's most used pieces of internet facing software that also isn't "a huge codebase"? Yes I do think nginx will be just fine. Security experts are constantly combing through that sort of software looking for holes, as well as AI tools. duh. It ups your brand to find holes.
- nxc18 7y agoCounterpoint: https://en.wikipedia.org/wiki/Heartbleed https://en.wikipedia.org/wiki/Heartbleed - 2 years is a long time
- kiney 7y agothe thing is: you have to introduce very subtle bugs when the code is open. And if you exploit it in the millions someone is going to notice.
- iforgotpassword 7y agoIndeed. If, as suggested, a backdoor is planted by something like a three letter agency they're not going for mass surveillance or "hacking all the things". It's a very valuable asset that you use wisely, maybe even just once if the target is worth being discovered afterwards.
- ajross 7y agoSomeone surely is doing regular thorough security audits of nginx, yes. Even at maximal cynicism, discovering a backdoor in its source code would get someone niche fame and a job at Project Zero (or a nice windfall on the black market, I guess).
- LinuxBender 7y agoNGinx is owned by F5 Networks [1]. F5 customers could probably open a case and ask what contingency plans are in place. [1] - https://www.f5.com/company/news/press-releases/f5-completes-acquisition-of-nginx https://www.f5.com/company/news/press-releases/f5-completes-...
- kayfox 7y agoNGINX still has separate support from F5 Support.
- LinuxBender 7y agoIs their support team in Russia? They may have their hands tied at the moment.
- lawnchair_larry 7y agoConspiracy theories are fun, but no, it doesn’t feel like an intelligence shakedown if you know even a little bit about intelligence shakedowns. Or about backdooring software. Clandestine ops have an extremely low probability of success using this strategy and nobody who does them is this incompetent. Especially not Russia.
- dmos62 7y agoI've some kind of reflex to say "come on, it can't be that bad over there", but then I read a thread like this and it's like a slap in my naivete's face. To put the "over there" remark in context, I grew up in a neighbourhing country.
- drosan 7y agoYep mate it totally can, stuff like that goes here on daily basis.
- edoo 7y agoThe last company I worked for put together a dev team in the Ukraine and poached some talent from a local company that was connected to the local government. Our company ended up paying a relatively small (significant in the Ukraine) 'fee' to not have the team physically shut down by the locals.
- rnhmjoj 7y agoThis reminded me the Lebedev institute situation from last month: https://www.nytimes.com/2019/11/07/world/europe/russia-raid-physics-institute.html?action=click&module=News&pgtype=Homepage https://www.nytimes.com/2019/11/07/world/europe/russia-raid-...
- egorfine 7y agoIt's pretty obvious to us, коллега, but that sounds absolutely crazy and conspiracy-like for outsiders of ex-USSR.
- stjohnswarts 7y agowow, I would have thought those dudes would have moved to a more friendly country years ago given the fame and profits from creating nginx.
- chr1 7y agoIt's frog in boiling water situation. For a long time the government was content with the money it could get from oil and mining, and many businesses were relatively safe. After the drop in oil prices and economic sanctions they started to get more creative, and the situation kept slowly worsening, until during this year there were multiple high profile cases like this.
- iaml 7y agoSome say Igor didn't move because he's a patriot. Ironic, isn't it?
- chr1 7y agoIt would indeed be ironic if he supports the current government. But in general patriot can also be someone who dislikes the crazy regime and doesn't want to give up his home without a fight.
- vthriller 7y agoWell, I wouldn't necessarily call him a patriot or regime supporter or whatever (not a vocal one anyways), but he indeed did like to occasionally throw some stones towards non-systemic opposition, color revolutions supporters, or other likely-minded people. One example would be what he wrote 12.12.2015 (exactly 4 years prior to current incident) at http://sysoev.ru/ http://sysoev.ru/ about Berezovskiy's alleged financial support of orange and tulip revolutions of 2004-5. So in that respect it isn't that impressive that he stayed in Russia even when (mostly non-state) news became more and more disturbing. Probably even less so if you assume a line of reasoning that nobody would bother with relatively small foreign company built around open-source product, a company that's already sold to larger foreign company (conveniently forgetting about the price that F5 paid for that company). (edit: s/american-registered/foreign/: Nginx Inc. was registered in British Virgin Islands)
- umvi 7y agoIt's easy to forget just how corrupt government and law enforcement can get. In America, try to bribe a police officer and you'll quickly find yourself in jail. Other countries, it's almost expected that you bribe police (and indeed, the true reason you just got pulled over might be to shake you down)
- ilikehurdles 7y agoDriving in several of the Balkans since the 90s with German license plates always required keeping some cash on hand to buy the officer's lunch. It's probably not true any more for Croatia since its acceptance into the EU, but we still had this experience in Bosnia and Serbia up through the 2010s.
- bnt 7y agoDoubt. Croatian police face hefty fines if they take bribe. Source: have several close friends in the police.
- ilikehurdles 7y agoI think I might have addressed this in an edit while your comment was posting. I agree fully on Croatia. It could happen in the 90s but the country has changed a lot since then.
- dboreham 7y agoThis is something we're working on though (in the US).