6 ms·
I have the full story on that incident. It is actually really funny. If the guy who did it wants to come forward, that is his decision. [edit: I won't name nam
by grugq 3y ago
I have the full story on that incident. It is actually really funny.
If the guy who did it wants to come forward, that is his decision. [edit: I won't name names.]
He did provided me the full story. He told me with the understanding that the story would go public, so I will dig it up and post it.
I also interviewed the sysadmins who were running the box at the time.
1. it was not an NSA operation, it was done by a hacker.
2. it was discovered by accident, not because of clever due diligence.
Basically, there was a developer who had a flakey connection and one time his commits didn't go through. To detect this in future he had a script that would download the entire tree from the server and compare it against his local copy to make sure that his changes had been committed.
It was discovered because of the discrepancy between his local working copy and the upstream copy. Which was checked not for security reasons, but because sometimes the two were out of sync. That's all. Just dumb luck.
The sysadmins are still quite bitter about it. I know how it feels when your box is hacked and you really take it personally.
The code wasn't added by hacking the CVS, as far as I remember, but rather through a hacked developer with commit rights.
that's the story as I was told
- causal 3y agoWait was the guy you know the hacker or someone who discovered the hack by accident? If the latter, how do you know anything about the hacker's identity or motive?
- ngneer 3y agoThat confused me, too. They appear to know the person who accidentally discovered the issue, not the hacker.
- jstanley 3y agoHow do they know it wasn't the NSA then?
- _notreallyme_ 3y agoThe guy who did it was quite vocal about it in some circles. It was a "for the lulz" kind of hack...
- netsharc 3y agoDeveloper tries to tell a story... Sounds like OP interviewed the person who uploaded the code, whose system was previously inflitrated (it can still be the NSA). So why say "If the guy who did it wants to come forward, that is his decision. But he did provide me the full story", it doesn't sound like OP interviewed the "guy who did it"...
- AnimalMuppet 3y agoI read that the other way. "If the guy who did it wants to come forward, that is his decision. But he [still talking about the guy who did it] did provide me the full story." That is, the perpetrator gave him the full story, but he won't name names, because it's the perpetrator's choice whether or not to reveal his identity.
- netsharc 3y agoOK, makes sense.. so the interviewed hacker mentioned that he got the code in by infiltrating the computer of "some developer"...
- deleted 3y ago[deleted]
- grugq 3y agothe hacker. I interviewed the sysadmins about it.
- ShamelessC 3y agoWhat is this a psi-op? This has been deeply frustrating to parse. You don't make sense.
- greggsy 3y agoIt’s the grugq.. he knows everything and everyone
- ajross 3y agoTo be clear: you're telling us the full story of the discovery, not the full story of the exploit? You and your source don't know who the attacker was, right?
- grugq 3y agoWhat is there to say about the hack? Like everything back then it was probably accomplished by exploiting trust relationships. I can ask him, but it is not at interesting 20 years later.
- spenczar5 3y agoIt is very interesting to prove whether or not it was a state actor! Surely you can see that that mystery is interesting to many people.
- dspearson 3y agoIt was not a state actor. There were plenty of high profile people and projects being owned just for the fun of it back then.
- epcoa 3y agoA state actor would have done a much better job. This was detected nearly immediately and anyone that knew how the system was setup (which was public knowledge) would have known this would be caught. The state level hackers are not that dumb. If there was a serious backdoor attempt, then this was the distractor. And seriously back in those days especially Linux didn’t need much help with getting root exploits in the tree.
- _notreallyme_ 3y ago> Like everything back then it was probably accomplished by exploiting trust relationships That's wrong on many levels. Bold and stupid "hacks" committed by teenagers using SE tend to get a lot of traction, because it is both bold and stupid. This hasn't changed. But "back then" there was much more than that...
- 3y ago
- mathverse 3y agoDid not cliph / wojciech purczynski also try to backdoor the kernel?
- hulitu 3y ago> 1. it was not an NSA operation, it was done by a hacker. Just like the NPR is not financed by the US government, but by NGOs.
- unethical_ban 3y agoNPR is not (majority) financed by the US government. https://www.npr.org/about-npr/178660742/public-radio-finances https://www.npr.org/about-npr/178660742/public-radio-finance... edit - removed some snark
- dspearson 3y agoNext we'll be hearing that ~el8 was a CIA front. :)
- deleted 3y ago[deleted]
- epcoa 3y agoGeez, this crowd. The clearest evidence that it was not an NSA attack is that it was not very good. It modified a CVS mirror. At no time was the source of truth (the bitkeeper repo) in any danger. Anybody that knew how this stuff worked at the time would have known it would be caught immediately. Not very state level expertise, pretty sad if it was the NSA.
- p-e-w 3y ago> The clearest evidence that it was not an NSA attack is that it was not very good. I suspect you are being sarcastic, but in case you aren't, you may want to reexamine your assumptions. The colossal incompetence that is synonymous with government work doesn't magically stop at three-letter agencies. The FBI/CIA communication fuckups before 9/11 are just one famous example. The idea that the NSA is staffed with "uber hackers" is a Hollywood fantasy. A government job working as a hacker is still a government job. Why would someone with that skillset, who can get a job at FAANG for 10x the salary, submit to the bureaucracy and monitoring BS that comes with working for an intelligence agency? I'm sure there are a select few who find this appealing, but the vast majority are just going the take the money and the free life.
- stevehawk 3y agomaybe 10x the salary (probably not) but also a correlated increase in hours instead of a contractually mandated maximum of 40 hours, combined with the legal inability to do work from home, discuss work at home, and a lot of related perks.
- p-e-w 3y agoAlso "perks" like having your life put under the microscope at regular intervals, going to prison if you talk about what you do, etc. And I strongly doubt that agencies that are known to routinely violate the law, the constitution, and human rights care about "contractually mandated" 40-hour workweeks.
- 3y ago
- k6k88 3y agoI remember the guy who did it from IRCnet #hax. He had many nicknames, but the one I knew him by was three characters long. I lost contact with him sometime around 2004-2005, and I occasionally wonder what happened to him and if he's still alive. I hope all is well.