4 ms·
Maybe I’m just being naive or too trusting, but this is sort of what I think when folks are getting worried about other backdoors like this in the wild. Is it
by xorvoid 3y ago
Maybe I’m just being naive or too trusting, but this is sort of what I think when folks are getting worried about other backdoors like this in the wild.
Is it that they just got unlucky to get caught, or is this type of attack just too hard to pull off in practice?
I’d like to think the later. But, we really don’t know.
- ordu 3y agoI feel the same way. It is too much complexity in one place, it couldn't work without hiccups.
- lyu07282 3y agoOne measure might be that we never really found that many backdoors. Over time there is quite a large accumulation of hackers looking at the most mundane technical details. This may be confirmed by regular vulnerabilities that are found in sometimes many decades old software, since vulnerabilities are much harder to find than backdoors. For example shellshock was 30 year old code, PwnKit 12 and log4j was ~10 ish. So if backdoors were commonplace, we probably would've found more by now. Perhaps that's changing now, the xz backdoor will for sure attract many copycats.
- sjs382 3y ago> Over time there is quite a large accumulation of hackers looking at the most mundane technical details. Are there though? Even if true, there are probably enough places with very few eyes on them.
- almostnormal 3y agoMaybe something could be built to put more eyeballs on things. A kind of online-tool that collects the sources to build some relevant distributions, a web front-end to show a random piece of code (filtered by language, probability to show inreasing by less-recently/frequently/qualified viewed) to a volunteering visitor to review. The reviewer leaves a self assesment about their own skills (feed back into selection probability) and any potential findings. Tool-staff double-checks findings (so that the tool does not create too much noise) and forwards to the original authors (bugs) or elsewhere (backdoors). A bit like wikipedias show random page.
- cjbprime 3y agoDoesn't your data prove the opposite point? There are so many vulnerabilities and so few people looking for them that even the thirty year old ones have barely been found. A healthy feedback loop would have trended the average age of each vulnerability at the time of detection to be *short".
- formerly_proven 3y agoMost backdoors that are found are really obvious garbage. Like hardcoded credentials or keys in appliances.
- brokenmachine 3y agoThis also had hardcoded credentials, just quite well obfuscated. So I learned yesterday what a Trie is. https://en.wikipedia.org/wiki/Trie https://en.wikipedia.org/wiki/Trie
- hinkley 3y agoI’m not convinced that if I found a bug that I’d notice all the security implications of fixing it. Occasionally yes, but I wonder how many people have closed back doors just by fixing robustness issues and not appreciated how big of a bug they found.
- beeboobaa3 3y agoSure, but this xz backdoor is far, far more involved than that.
- breadwinner 3y agoThey could have covered tracks better. So says Andres Freund, the person who discovered the backdoor: https://news.ycombinator.com/item?id=39923467 https://news.ycombinator.com/item?id=39923467
- devcpp 3y agoNote he's not a cybersecurity researcher, he's mostly a database engineer (a great one, making significant PGSQL contributions), so I'm not sure he's familiar with statistics and variety of backdoor attempts.