Discussion about this post

User's avatar
lcamtuf's avatar

Update: a more detailed analysis of the payload is here:

https://bsky.app/profile/filippo.abyssdomain.expert/post/3kowjkx2njy2b

Plus, a good summary of the obfuscation mechanism can be found here:

https://gynvael.coldwind.pl/?lang=en&id=782

An interesting question that I didn't address in the article is whether the group behind xz would be putting all their eggs in one basket - i.e., are there more backdoors of this type waiting to be found?

I think the "one basket" theory is fairly likely. Running multiple similar projects in parallel paradoxically *reduces* the odds of success. Probability of discovery goes up - and once one is found, people start looking for the patterns elsewhere. If my reading of the situation is correct, we're talking about people who understand this.

This is not an argument to stop looking, especially since there were numerous (less sophisticated) attempts to backdoor OSS before, and there will be more in the future. But I wouldn't be surprised if we come up empty-handed.

Expand full comment
lcamtuf's avatar

For the record, I did some comment cleanup on this thread. First, there was a lot of repetitive questions and debate about one word - "foreign" - that is no longer in the article. I left one question and response for posterity, but I don't think there's much else to say.

Second, there was a flurry of whataboutist comments from people who weren't subscribed at all or joined moments before. While I normally don't curtail debate... if you're not really interested in this Substack and just want to offer snarky wisdom about Snowden or Russia, please do it on your own blog.

Expand full comment
32 more comments...

No posts