3 ms·
I added a lot more in the previous thread from yesterday (didn't get on the front page but would be good to merge into this thread)[1]. In summary: Australia h
by dhx 2y ago
I added a lot more in the previous thread from yesterday (didn't get on the front page but would be good to merge into this thread)[1]. In summary:
Australia has laws such as [2][3] (in the state of NSW) which prohibit possession of encrypted communications devices which are deemed to be purpose designed for use in the illicit drug trade or some other defined criminal purposes. The accused application developer/administrator is alleged to have specifically built the application for use in the illicit drug trade with no other reasonable reason for the application existing. Access to the application was by invitation only with allegedly 600-something installations out there, with these installations stated to be overwhelming associated with the illicit drug trade and criminal groups.
In addition to outlawing encrypted communications devices deemed to be designed only for use by criminal groups, Australia has multiple other laws that compel anyone able to assist with breaking into a computer system or messaging service to do so. In this case, it appears a warrant allowing the application to be backdoored was granted, and this backdoored app was then distributed to the 600-something devices allowing messages to be read. The accused application developer/administrator seemingly wasn't aware. Likely it won't be revealed what the exact method used was, but it could theoretically include black bag operations and compelling third parties to assist with access to data centres, servers, networks, etc.
Seemingly the primary concern for you is if at least one person using your code is in the illicit drug trade (even if 99.99% of the other users of the code are law abiding citizens), you could perhaps be compelled in at least Australia (but also a rapidly growing list of other countries) to insert a targeted backdoor into the code. A similar situation to the xz-utils backdoor but with a law-abiding developer being compelled to insert the backdoor themselves. Or alternatively, if you host the code on GitHub or on a rented server, Microsoft or a hosting provider is compelled to hand over the GitHub account or rented server to assist with attacking the target illicit drug trade user. With more and more countries copying this attack model, it'll seemingly wreck havoc on software supply chains and the software industry generally. Software will become increasingly nationalised and the Internet's global reach further dismantled. Possibly it will become quite difficult for software developers to take a holiday or attend a conference in a different country.
Possibly the best current defence against such supply chain attacks is something similar to Gentoo's package repository (monolithic Git repository) which ensures software cryptographic checksums are shared globally. For a supply chain attack to work, malicious software is required to be distributed to everyone at once, thus making the supply chain implant detectable and observable to everyone. Some of the more recent attempts at introducing Software Bill of Materials (SBOM) also try to achieve a similar objective. All of these have a single-point-of-failure aspect, which an alternative distributed ledger approach helps solve.
[1] https://news.ycombinator.com/item?id=41566948 https://news.ycombinator.com/item?id=41566948
[2] https://legislation.nsw.gov.au/view/html/inforce/current/act-1900-040#sec.192O https://legislation.nsw.gov.au/view/html/inforce/current/act...
[3] https://legislation.nsw.gov.au/view/html/inforce/current/act-1900-040#sec.192P https://legislation.nsw.gov.au/view/html/inforce/current/act...
- ColinWright 2y agoThat's useful ... thank you. Bookmarked for reference. (FWIW, the web site in your profile isn't loading)