Everything I know about the XZ backdoor xz-utils backdoor situation
A summary of the xz-utils backdoor incident is as follows
dmikurube Amazing. Three years of building trust and planting backdoors. It's like a thousand years of work to trick the demon tribe, but there's actually an incentive to do this... [Everything I know about the XZ backdoor https://boehs.org/node/everything-i-know- about-the-xz-backdoor] dmikurube The fact that the maintenance of these things is on the shoulders of individuals, and the fact that it was almost entirely the work of individual craftsmanship that detected them... What can I say? dmikurube But the fact that there was one of these, I guess I should see that there are others. Ugh. dmikurube In the open source culture, there are many people who say "I'm waiting for your contribution", but it is difficult to see examples like this. But when I see examples like this, it's difficult. But as a maintainer, I can't accept it so lightly. dmikurube (I am quite bitter about people who complain like that. Even if I am not the maintainer.) dmikurube In fact, with Embulk, if you can sneak in a little work, you can probably divert data from one company to another. I'm watching it carefully. Many plug-ins are out of our jurisdiction, though. dmikurube I try not to carelessly use third-party actions like GitHib Actions. It's a good target to do something. And typically, Gradle plugins... dmikurube "In April 2022, Jia Tan submits a patch via a mailing list. The patch is A new persona - Jigar Kumar enters, and begins pressuring for this patch to be merged." Wow. I guess those who pressure people to "merge this" should be classified as the same. "In April 2022, Jia Tan submitted a patch via the mailing list. The patch is irrelevant, but the events that follow are irrelevant. A new persona - Jigar Kumar - comes in and starts pressuring us to merge this patch. Wow. I guess those who pressure you to "merge this" should be judged the same way. dmikurube "Soon after, Jigar Kumar begins pressuring Lasse Collin to add another In the fallout, we learn a little bit about mental health in open source. "Shortly thereafter, Jigar Kumar began pressuring Lasse Collin to add another maintainer to XZ. As a result, we can learn a bit about mental health in open source" Hmmm...
izutorishima wow, they spent 3 years contributing to xz-utils to win their trust and then put a backdoor in... too egregious! ...... I can only say that it was a coincidence that I found it, and if it had gone around to Ubuntu or something, I'd be scared to log in to any public server that sshd's out to without a password.
piro_or The colors.js debacle was about the developers themselves messing things up, not necessarily because it was open source, [WinGroove Incident WinGroove, but it is a story that only open source can tell, where the developer has gained trust through contributions and even commit privileges, and then becomes an attacker. piro_or WinGroove case, could it now be the subject of an investigation for unauthorized electromagnetic recording?
nishio Given the law of "a fraud that is found is a fraud that is poorly covered up", you found a remote login backdoor in xz and dealt with it while you still can. I'm glad you were able to do it. ......, but it's more likely that a similar backdoor was planted in something that isn't known and is spreading.
This page is auto-translated from /nishio/xz-utilsバックドア事件 using DeepL. If you looks something interesting but the auto-translated English is not good enough to understand it, feel free to let me know at @nishio_en. I'm very happy to spread my thought to non-Japanese readers.