this post was submitted on 31 Mar 2024
587 points (97.6% liked)
Open Source
31258 readers
184 users here now
All about open source! Feel free to ask questions, and share news, and interesting stuff!
Useful Links
- Open Source Initiative
- Free Software Foundation
- Electronic Frontier Foundation
- Software Freedom Conservancy
- It's FOSS
- Android FOSS Apps Megathread
Rules
- Posts must be relevant to the open source ideology
- No NSFW content
- No hate speech, bigotry, etc
Related Communities
- !libre_culture@lemmy.ml
- !libre_software@lemmy.ml
- !libre_hardware@lemmy.ml
- !linux@lemmy.ml
- !technology@lemmy.ml
Community icon from opensource.org, but we are not affiliated with them.
founded 5 years ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
view the rest of the comments
The guy was from Hong Kong, they probably threatened to throw his family in jail.
he was using a singapore VPN and had access to multiple sockpuppets. we know literally nothing else about them and anything you've heard to the contrary is baseless rumor.
leading theory is that it was a state-sponsored actor, but frankly even that much is speculation and which state is still way up in the air.
It seems I'm out of the loop, how do we know about hongkong and singapore?
we know about the singapore VPN because they connected to IRC on libera chat with it. the only reason I can think people would believe they're from hong kong is because of the pseudonym they used, but it's not like that proves anything.
see link posted in another user's reply: https://boehs.org/node/everything-i-know-about-the-xz-backdoor#irc
Hmm.
I don't know if the VPN provider is willing to provide any information, but I wonder if it's possible to pierce the veil of VPN in at least approximate terms?
If you have a tcpdump of packets coming out of a VPN -- probably not something that anyone has from the Jia Tan group -- you have timings on packets.
The most immediate thing you can do there -- with a nod to Cliff Stoll's own estimate to locate the other end of a connection -- is put at least an upper bound and likely a rough distance that the packets are traveling, by looking at the minimum latency.
But...I bet that you can do more. If you're logging congestion on major Internet arteries, I'd imagine that it shouldn't take too many instances of latency spikes before you have a signature giving the very rough location of someone.
Some other people pointed out that if they used a browser, it may have exposed some information that might have been logged, like encodings.
I don't foresee anyone with the kind of data needed to do more investigation releasing it to the public, so I doubt we're going to be getting any satisfying answers to this. Microsoft may have an internal team combing through github logs, but if they find anything they're unlikely to be sharing it with anyone but law enforcement agencies.
Via https://boehs.org/node/everything-i-know-about-the-xz-backdoor
Wild, so it would suggest that the actor wasn't Chinese at all. An authentic Chinese person probably wouldn't choose a name that sounded like that, any more than I would name myself Sean MacBerkowitz, it would just sound wrong.
A random name generator might produce something like this, of course, if it wasn't programmed to be too picky.
Or they are Chinese, and pick non-authentic Chinese names so people wouldn't suspect them? I don't think looking at the name can be a great way to identify the source.
This attack is clearly sophisticate: the attacker(s) are probably well-trained in obscuring their identity to not reveal much info from their name picks. Say, just use a random name generator.
Except it is a Chinese name, as Cantonese is spoken in China. Lots of speculation here by people missing vital information.
The name is suspicious because "Jia Cheong Tan" uses two different romanization of Chinese used in different regions. "Jia" and "Tan" seems to be pinyin, which is commonly used in the mainland; yet "cheong" uses probably Wade-Giles which is used in Taiwan.
OP seems to suggest cheong is Jyuping, which is used as a romanization for cantonese, but according to wikipedia, "eong" is not a final for Jyuping. So I don't think this is Jyuping.
disclaimer: I don't know a lot about Jyuping or Wade-Giles, so everything I put out is from wikipedia.
See: