7 ms·
Half a Second – a book about the XZ backdoor
- OldMatey 3mo agoGiven the time and effort that went into this, and the luck that one diligent person noticed, investigated and discovered what was going on before it could get further... it seems very likely to me that this has happened already in other libraries without being discovered.
- miramba 3mo agoExactly, and I wonder since then: How closely did people in comparable situations look? Since nothing similar has been reported, I suspect not very close…
- VladVladikoff 3mo agoI wonder if the nation state actors are doing people profiling on owners of important packages to find the most vulnerable for an attack.
- akimbostrawman 3mo agoAnybody running opensnitch would notice
- IshKebab 3mo agoThe effort of gaining trust over an existing project isn't even really required. All you need to do is monitor when popular GitHub repos get archived. That's usually when the original authors don't want to work on it any more. Then just quickly make a fork to continue the project (think Phabricator -> Phorge), and if you're quick enough and authoritative sounding enough, boom control of the project! Maintain it for a bit so people switch to your version, and job done.
- lucasRW 3mo agoIt's only going to recycle old news. The missing piece is attribution. Had it been the usuals (DPRK, Russia, China), the attribution would have been made publicly. The fact that is has not points as a friendly - especially when Microsoft (who owns Github) had all that telemetry and very likely has the means to find out. Some serious OSINT (consistency of timezone across months if not years of commits) pointed to the Middle East. An obvious Unit name comes to mind.
- diogocp 3mo agoFun fact: the guy who reported it (Andres Freund) works for Microsoft. Another fun fact: Moscow is in the same time zone as the Middle East.
- anonreplier 3mo ago"all that telemetry" doesn't count for much if it's behind a VPN
- lucasRW 3mo agoHighly debatable. Threat-hunting at that level can easily use VPNs to make attributions, especially if those same VPN exit points happen to be correlated to other stuff that was attributed. And when you are Microsoft or Google (Jia Tan had gmail accounts), the telemetry they have goes way beyond "oh we can't see the real IP lolz". The group responsible for the xz attempted compromise is circulating in certain Chatham House rules conference. It's just that, as someone there said "no one has had the balls to say it publicly", which in itself gives a strong hint.
- kreyenborgi 3mo ago> The catch is where the book begins, not what it is about.
- edblair 3mo agoHalf expecting the next few paragraphs to contain, verbatim, "The smoking gun was a performance issue in a development build of Debian. It's was a sharp observation, and sharper than you may think."
- this_user 3mo agoWell, the "About the Author" section should probably just be a link to claude.ai.
- sevg 3mo agoYeah the (annoyingly) excessive use of colons feels like recent Claude models to me. Looks like author posted this themselves earlier, and even used Claude for the HN comment: https://news.ycombinator.com/item?id=48958457 https://news.ycombinator.com/item?id=48958457
- infinite_spin 3mo agoI've always used a lot of semi-colons in my writing, especially in my technical writing. So I did a search on this pdf for semi colons, and there are 260 in a 264 page document. I then repeated this for the last book I read, Candide by Voltaire, and there were 507 semi colons in a 189 page book. This seems like a witch hunt.
- rwmj 3mo agoI read parts of it, being first hand involved in all this, and it seems like it was written by AI to me. If you used an AI to write it or help with it, why not just admit to it?
- infinite_spin 3mo agothe argument was that use of semi-colons indicates AI usage.. what do you mean by "being first hand involved in all this"? what part did you take if you don't mind sharing, this was an incredibly interesting turn of events.
- rwmj 3mo agoYou'd know that if you'd done any research at all. Compare this to Jeff Guo (NPR) or Henry van Dyck (Veritasium) or my contact at the WSJ. They all investigated this story, interviewed key people (more people were interviewed for the Veritasium video than appeared), and fact-checked everything with subject matter experts. The NPR story took about 3 months of work and the Veritasium video took 5 months. I was interviewed in total for over 6 hours across all of them. These are real journalists who worked on these stories and they produced novel work and new findings. I have huge respect for them, especially after being involved with it and seeing what work it took to add something new to the story. At the same time they managed to tell that story to a lay audience which is another skill in itself.
- tryauuum 3mo agoSo Microsoft did something good? I thought they are too busy keeping my personal data in a prison and writing tight bash loops wasting 100 percent of a core
- akimbostrawman 3mo agono, someone who just happens to work for microsoft doing something at home did something good.
- dhx 3mo agoSee [1] for April 2024 Clickhouse Github activity analysis of the xz backdoor. I haven't seen anyone write up a proper analysis that includes consideration of: - GitHub activity (e.g. all API actions on GitHub side including replying to comments) _and_ mailing list activity _and_ other public facing activity all considered together. - Complexity of public actions e.g. was there a queue of code changes that would have taken 20 hours effort to put together that were all committed at once? Were there any long streaks of high activity where it might reveal how many people were involved? - Latency of public actions e.g. if an issue was raised by some random person, how long did it take for the attacker to respond, and later resolve/commit a patch? Similar to the complexity of public actions, it might reveal how many people were involved by estimation of the time needed for an experienced developer to fix an issue vs. actual time taken, both in terms of level of effort and duration. - International dispersement of a team in different timezones with some core hours for collaboration, review and public facing activity. - Public holidays, country/region-specific work habits, etc--e.g. consideration of "summer holiday" periods or similar common holiday periods, consideration of unusual days of no/low activity versus snow days, power outages, etc which might have been experienced by the attacker. Distribution of actions from Github indicates the attacker used a 6 day work week excluding Sunday, and almost all activity conducted between UTC 12:00-16:00. Within these 6 days, activity was uneven at 0.5, 1, 1, 1, 1, 0.5 effort per day. There are low activity periods too that line up with summer solstice (southern hemisphere) or winter solstice (northern hemisphere). There are interesting patterns in the data not yet publicly analysed (I think?) that seemingly would reveal the true location of attackers, particularly because attacker actions are anchored to uncontrollable events such as a known-good contributor (such as Linux distro maintainer) raising a Github issue against a repository and the attacker replying an hour later. For such events with low latency of reply, it'd be well worth considering when a reply was made quickly, and when it wasn't, across a few years of data points. [1] https://news.ycombinator.com/item?id=39905375 https://news.ycombinator.com/item?id=39905375
- skippyfish 3mo agoHere's the tool developed by the author that was almost certainly used to generate this book in its entirety - "A structured pipeline for writing long-form nonfiction, packaged as a Claude Code skill": https://github.com/AdrianMastronardi/bookwright https://github.com/AdrianMastronardi/bookwright There's nowhere near enough public information about the xz vuln to be worth turning into a book, so the merits of AI-generated text aside, this is just a very inefficient way to learn about the topic.
- eth0up 3mo ago"There's nowhere near enough public information about the xz vuln to be worth turning into a book," As an actual person, who reads, and having glanced at this book, I do not agree. I can already see part of the purpose is to put perspective on the crazy reality of backdoors/exploits and the undermined implications thereof. Jia Tan alone could warrant a book or film. It also says "for the general reader" and non-technical, which is where I myself think the importance really is. Maybe the AI is catching blindspots. I downloaded the book. It's not fake. Perhaps no masterpiece, but far from worthless. Also, not "enough public information" really sells inference and imagination short. There is a rich amount of material to work with here. More than enough. I am going to go ahead and say that flagging this was more information suppression than crankiness about AI. A lot of folks get strange when Jia Tan or similar subjects come up. I guess it's wiser to just wait until the grid goes down, or the water supply gets a bit more chlorinated....
- pflenker 3mo agoIt’s great to have the entire topic brought together into a cohesive book - but wow, I find it very annoying to read.
- ptx 3mo agoProbably because LLM output only gives the appearance of cohesive writing, but the more you try to understand the author's intent and meaning, the more confusing and annoying it gets, as there is no author, no intent and no meaning there to understand.
- pflenker 3mo agoThat’s not it in this case, because the book is mostly a recounting of what happened. I narrowed it down to two things: One is that every aspect of the story is treated equally - unimportant facets get an equally profound sounding prose like the really important bits. And the other one is the repetition of phrases. Everything is worth slowing down on.everything is load bearing. That’s so annoying.
- ptx 3mo agoRight, that's the sort of thing I meant. As you read it, you would naturally try to understand why the author used such profound-sounding prose in that particular part of the text. You would expect that the author's intent was to emphasize the important bits. When the author talks about slowing down or something being load-bearing, you would expect that they're going somewhere with this, that this particular bit is especially important in some way. But with an LLM-generated text, these attempts at understanding will get you nowhere and only produce frustration. The reader is left trying to interpret a signal that isn't really there.
- ethanhawksley 3mo agoI've also been working on a free book about the XZ backdoor called 500 milliseconds. However, unlike this author it is entirely human written. A first draft is ready and I'm aiming to publish in a couple weeks
- ethanhawksley 3mo agoI might even need to change the name of the book
- ethanhawksley 2mo agofor future reference, I've since renamed the book to "The Second Maintainer"