Elektrine lite

← Feed

@corbet@social.kernel.org

Post #2092814

2024-03-29 19:54 UTC

Random, unordered, probably useless thoughts on today's apocalypxze... Part of the success in getting this into Debian may be the result of there being no xz maintainer there. It is "maintained" by people whose attention is normally elsewhere doing occasional non-maintainer updates. This code will have been running on the machines of a lot of distribution maintainers. If it has already been exploited, it could be that its real purpose has already been achieved and the real problem is now elsewhere. I sure hope somebody can figure out a way to determine if this backdoor has been used. The multi-front nature of the attack, including multiple efforts to get the malicious code installed more widely more quickly, suggests we're not just dealing with a lone sociopath. I fear we'll never know who was really behind this, but I would sure like to. There is surely more where this cam from.

Replies (12)

  • @drewdaniels@mastodon.online 2024-03-29 20:08

    @corbet it may already be more widespread https://infosec.exchange/@mikesiegel/112180553308563886

    Open ##2095326

  • @brauner@mastodon.social 2024-03-29 20:44

    @corbet https://lore.kernel.org/lkml/20240320183846.19475-2-lasse.collin@tukaani.org/

    Open ##2095327

  • @soaproot@sfba.social 2024-03-29 20:50

    @corbet Ooh interesting. I was just thinking of reproducible builds given the portion of the backdoor not in the source distributions. But your point about code without maintainers who are on top of changes is perhaps even more fundamental.

    Open ##2095328

  • @noahm@chaos.social 2024-03-29 20:57

    @corbet This concern was even called out during the ingestion process for the backdoored version. https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1067708#27 The fact that the upload was being performed by one of the upstream contributors no doubt went a long way toward assuaging those concerns at the time.

    Open ##2095329

  • @ck@chaos.social 2024-03-29 20:57

    @corbet Not necessarily, though a maintainer would certainly be a good idea. Apparently, the author of the backdoor lobbied aggressively with the Fedora maintainers and managed to sneak it by them: https://news.ycombinator.com/item?id=39865810#39866275

    Open ##2095330

  • @jmm@fosstodon.org 2024-03-29 21:01

    @corbet I don't think the Debian maintenance state was relevant here. The malicious releases equally landed in other distros and the attacker e.g. pushed for pulling 5.6.1 to Ubuntu noble. In fact the last upload prior to the security revert officially changed the maintainer field to what was already the defacto xz maintainer in Debian: https://tracker.debian.org/news/1515323/accepted-xz-utils-561-1-source-into-unstable/

    Open ##2095331

  • @mirabilos@toot.mirbsd.org 2024-03-29 23:40

    @corbet people are currently looking into rolling back at least amd64 to before the 5.6.x uploads at least. Also, who knows what other, perhaps more subtle, backdoors were placed in the years #JiaT75 had full project access… (a further reverting of xz is being discussed but not as easy) … and what other #Debian sponsorship requests this “Hans” made…

    Open ##2095332

  • @fenruspdx@fosstodon.org 2024-03-29 23:49

    @corbet would not be surprised if this was a case of "state actor". oh well -- that was a fun afternoon removing liblzma from as much of the distro as possible since well -- no more trust. (we got lucky in that our sshd did not link to liblzma at least)

    Open ##2095333

  • @siguza@infosec.space 2024-03-29 23:50

    @corbet the sshd part suggests that it was specifically targeting servers, and obviously there is unimaginable potential if you had a backdoor on servers hosting important stuff (think GitHub or Debian package mirror), but I'd hope that those types of servers wouldn't yet be running any backdoored builds, since this was caught before it landed in stable (by sheer dumb luck though).

    Open ##2095334

  • @fenruspdx@fosstodon.org 2024-03-30 00:23

    @corbet also of note is that we found that "libarchive" was released/signed by the same gpg key/author so that obviously should be treated with suspicion as well

    Open ##2095335

  • @zeruch@mastodon.social 2024-03-30 04:39

    @corbet the scuttlebutt seems to suggest a state or state-adjacent actor/entity at fault. Do you feel that's over the top or in the proximity of likely?

    Open ##2095337

  • @corbet We might not *know* where it came from but the same people trying to get loongarch patches into things is certainly... a clue

    Open ##2095338