3 ms·
> Given how easy the infiltration is and how extremely hard to detect it is, likely a lot. I read it exactly the other way around: the infiltration took years
by david_draco 3y ago
> Given how easy the infiltration is and how extremely hard to detect it is, likely a lot.
I read it exactly the other way around: the infiltration took years and detecting it was the default with a fuzzer, which had to be disabled for the exploit to succeed.
It speaks to the hardening and that hardening should be required more. And of course the precarious roles of maintainers, which have been discussed elsewhere.
- dullcrisp 3y agoThe exploit could be detected with a fuzzer perhaps. The infiltration seems like it was something that would be very easy for a funded intelligence agency to do, and would be nigh undetectable if they had been subtly introducing bugs rather than shipping a sophisticated backdoor to every Linux distro. You have to assume if this was an intelligence agency they didn’t burn their only agent like this.
- HankB99 3y ago> they didn’t burn their only agent like this. I think I'd characterize that as "their only identity." What's the chance that some number (>1) of actual agents were sharing this identity? If that's the case, I'd extrapolate that to multiple identities. In fact the social engineering to gain the trust of the original maintainer likely involved several identities. I suspect that detectability of intentionally injected bugs would be very low.
- Thorrez 3y ago>a fuzzer, which had to be disabled for the exploit to succeed. According to this comment, the fuzzer wouldn't have detected it. It wasn't necessary to disable the fuzzer: >https://news.ycombinator.com/item?id=39911249 https://news.ycombinator.com/item?id=39911249
- geggo98 3y agoYou are right, it took quite some time. On the other hand, it looks like the legitimate part of contributing to xz was only a part time job for the attacker. The rest of the time, they either worked on the exploits, or in other things, like infiltrating other projects using a different handle. Basically I can imagine the attackers being a well organized group, using work sharing and pipelining. Some members of the group would be preparing exploits, some would infiltrate projects and some would make sure not to get caught. And since infiltrating takes time, they would make sure to have multiple projects in the pipeline, seine in the early contributor stage, some in the social pressure stage, and some in the exploiting stage.