4 ms·
A Chinese name is consistent with the timezone - alternatively Australia, Russia etc. Here is my speculation. I would look at the test framework - the attacke
by throwaway4good 2y ago
A Chinese name is consistent with the timezone - alternatively Australia, Russia etc.
Here is my speculation.
I would look at the test framework - the attacker needs the complexity of it to hide away the attack and it is first thing he publishes - probably has been planned from the very beginning.
This is a homemade thing based on something called "Seatest".
How common is Seatest? Not that common as far as I can tell - maybe someone can correct me?
- Tarq0n 2y agoUTC+1-3 are west to middle European time zones.
- thrdbndndn 2y agoUTC+1/3 is NOT consistent with China's timezone.
- throwaway4good 2y agoI was referring to the time zone of +8 used in the git commits mentioned here: https://www.wired.com/story/jia-tan-xz-backdoor https://www.wired.com/story/jia-tan-xz-backdoor The Mystery of ‘Jia Tan,’ the XZ Backdoor Mastermind The thwarted XZ Utils supply chain attack was years in the making. Now, clues suggest nation-state hackers were behind the persona that inserted the malicious code. ... At a glance, Jia Tan certainly looks East Asian—or is meant to. The time zone of Jia Tan’s commits are UTC+8: That’s China’s time zone, and only an hour off from North Korea’s.
- defrost 2y ago> or is meant to. Indeed. If it's nation state and years in the making then the idea of all the commit times being faked isn't a stretch. Hell, even five-eyes (UK+AU+US+etc) could seek a linux backdoor and use Perth, Australia (GMT+8) timezones or have a submission bot in the UK that just commits at preset time from preset IP proxy.
- throwaway4good 2y agoI would guess the guy that maintained the Jia Tan identity was working out of Australia. The time zone is consistent with Western Australia and the work starts by "branching out" a not widely used Australian test framework. The actual attack is probably done by someone else.
- lyu07282 2y agoWhat is seatest? Can you elaborate? That's the first time I heard that mentioned
- throwaway4good 2y agohttps://github.com/keithn/seatest https://github.com/keithn/seatest Which Jia Tan turns into "s-test".
- lyu07282 2y agoThey used test driven development for the backdoor development? Kind of hilarious ngl
- throwaway4good 2y agoYes. Test is a perfect place to hide an attack - reviewers pay far less attention to test code than the (what they perceive to be) production code.