4 ms·
I don't want to read too much into it, but the person (supposedly) submitting the PR seems to work at 1Password since December last year, as per his Linkedin. (
by Bromeo 3y ago
I don't want to read too much into it, but the person (supposedly) submitting the PR seems to work at 1Password since December last year, as per his Linkedin. (And his Linkedin page has a link to the Github profile that made the PR).
- returningfory2 3y agoYeah the GitHub account looks really really legitimate. Maybe it was compromised though?
- jethro_tell 3y agoWhat looks legit about a gmail address and some stock art for a profile?
- gpm 3y ago[Deleted per below]
- TeMPOraL 3y agoCan you stay in that org after leaving Google?
- Jyaif 3y agoYou are not looking at the right profile. This is the profile that people are talking about: https://github.com/jaredallard https://github.com/jaredallard
- gpm 3y agoOops, you're absolutely correct. Deleted (via edit) my comment above. Thanks.
- ncr100 3y agoHe was just (50 minutes ago) removed from the oss fuzz repo. I hope this also (at least temporarily until verification of 'bad/good') remove him from the org?
- buildbot 3y agoPlus the README.md that is just a rickroll
- ncr100 3y agoThe 2 GMail accounts are 85% / mainly associated with XZ work, since 2021, per searching for them explicitly via Google.
- computerfriend 3y agoThe PR's two commits are signed by a key that was also used to sign previous commits belonging to that author.
- dralley 3y agoHold up, are you saying that https://github.com/jaredallard https://github.com/jaredallard and the accounts affiliated with this XZ backdoor share a PGP key? Or something else?
- computerfriend 3y agoNo, this account made a PR and their commits were signed [1]. Take a look at their other repositories, e.g. they did AoC 2023 in Rust and published it, the commits in that repository are signed by the same key. So this is not (just) a GitHub account compromise. I find this aspect to be an outlier, the other attacker accounts were cutouts. So this doesn't quite make sense to me. [1] https://github.com/jamespfennell/xz/pull/2/commits https://github.com/jamespfennell/xz/pull/2/commits
- bombcar 3y agoIf I were trying to compromise supply chains, getting into someplace like 1Password would be high up on the list. Poor guy, he's probably going to get the third degree now.
- switch007 3y agoAs a 1Password user, I just got rather nervous.
- lelandbatey 3y agoThey're definitely a real person. I know cause that "1Password employee since December" is a person I know IRL and worked with for years at their prior employer. They're not a no-name person or a fake identity just FYI. Please don't be witch hunting; this genuinely looks like an unfortunate case where Jared was merely proactively doing their job by trying to get an externally maintained golang bindings of XZ to the latest version of XZ. Jared's pretty fantastic to work with and is definitely the type of person to be filing PRs on external tools to get them to update dependencies. I think the timing is comically bad, but I can vouch for Jared. https://github.com/jamespfennell/xz/pull/2 https://github.com/jamespfennell/xz/pull/2
- greatjack613 3y ago[flagged]
- lelandbatey 3y agoHere's a PR on an employer-owned public Github repository where I made a change and Jared approved it. Please, let's not witch hunt. https://github.com/getoutreach/stencil-golang/pull/404 https://github.com/getoutreach/stencil-golang/pull/404