Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > linux.debian.user > #268673
| From | Roberto C. Sánchez <roberto@debian.org> |
|---|---|
| Newsgroups | linux.debian.user |
| Subject | Re: making Debian secure by default |
| Date | 2024-04-01 05:00 +0200 |
| Message-ID | <Iog3T-39HL-1@gated-at.bofh.it> (permalink) |
| References | (5 earlier) <In22Z-2kwg-5@gated-at.bofh.it> <InnK9-2z9u-1@gated-at.bofh.it> <Inodb-2zyy-9@gated-at.bofh.it> <IodIK-38gI-3@gated-at.bofh.it> <IoeY9-38VA-5@gated-at.bofh.it> |
| Organization | linux.* mail to news gateway |
On Mon, Apr 01, 2024 at 01:45:07AM +0000, Andy Smith wrote: > Hi, > > On Sun, Mar 31, 2024 at 07:19:41PM -0500, Nicholas Geovanis wrote: > > I would think A Smith's comment here was directed to this interesting bit > > from the report he cited: > > > > Given the activity over several weeks, the committer is either directly > > involved or there was some quite severe compromise of their > > system. Unfortunately the latter looks like the less likely explanation, > > given > > they communicated on various lists about the "fixes" mentioned above. > > > > End quote. > > I don't really want to go much further into this as the person I > responded to was clearly further upset by what I said, but all I was > suggesting was not getting too worked up about things that are so > far out of one's control. > > To bring this sort of thing somewhat more under humanity's control > is going to take some very large scale reworking of how the open > source software supply chain works, possibly even how society works. > It's not something that can be achieved by an end user with a best > practices document or a security checklist. Unless step one on the > list is "give up general purpose computing." > > In the xz case the further you go looking for a root cause the wider > the implications are: > > Q: Why was there a back door in sshd? > A: Because some malicious code was linked to it. > > Q: How did malicious code get linked to it? > A: Its lzma dependency was compromised. > > Q: Who compromised the lzma dependency? > A: One of the developers of that project who had full rights to > commit code to it. > > Q: Why did a persona that no one knows anything about get full > access rights to a code repository that is linked to openssh? > A: Because they did some work over a period of years that looked > genuine and the single other developer who was overwhelmed with work > decided to give them access based on that > > Q: Why did lzma, a dependency of openssh, have a single overwhelmed > developer? > A: Because no one felt the need to pay a team of developers to work > on it or audit work on it. > I love this. It's a great example of the "5 whys" (I know one of the 5 here was technically a "how", but could have just as easily been rephrased as a "why"). The final answer isn't comforting, but it certainly provides a clear and actionable path: "ensure critical projects aren't understaffed." It seems like an extremely obvious thing, the sort of thing that we wouldn't let happen. But then this XKCD from a year or two ago wouldn't be such an accurate representation of so many projects: https://xkcd.com/2347/ (I'm sure it's probably been linked in a 1,000 different threads in a 1,000 different forums related to this problem by now.) Regards, -Roberto -- Roberto C. Sánchez
Back to linux.debian.user | Previous | Next — Previous in thread | Next in thread | Find similar | Unroll thread
making Debian secure by default Lee <ler762@gmail.com> - 2024-03-27 22:40 +0100
Re: making Debian secure by default Andy Smith <andy@strugglers.net> - 2024-03-28 00:10 +0100
Re: making Debian secure by default Lee <ler762@gmail.com> - 2024-03-28 05:30 +0100
Re: making Debian secure by default Andy Smith <andy@strugglers.net> - 2024-03-28 14:40 +0100
Re: making Debian secure by default Greg Wooledge <greg@wooledge.org> - 2024-03-28 16:30 +0100
Re: making Debian secure by default Hans <hans.ullrich@loop.de> - 2024-03-28 16:50 +0100
Re: making Debian secure by default Lee <ler762@gmail.com> - 2024-03-28 19:20 +0100
Re: making Debian secure by default Ralph Aichinger <ra@h5.or.at> - 2024-03-29 08:50 +0100
Re: making Debian secure by default Stefan Monnier <monnier@iro.umontreal.ca> - 2024-03-29 20:10 +0100
Re: making Debian secure by default Jeffrey Walton <noloader@gmail.com> - 2024-03-29 20:40 +0100
Re: making Debian secure by default Andy Smith <andy@strugglers.net> - 2024-03-28 17:00 +0100
Re: making Debian secure by default Lee <ler762@gmail.com> - 2024-03-28 21:20 +0100
Re: making Debian secure by default Curt <curty@free.fr> - 2024-03-28 18:50 +0100
Re: making Debian secure by default Lee <ler762@gmail.com> - 2024-03-28 20:40 +0100
Re: making Debian secure by default Andy Smith <andy@strugglers.net> - 2024-03-29 18:00 +0100
Re: making Debian secure by default Joe <joe@jretrading.com> - 2024-03-29 18:30 +0100
Re: making Debian secure by default Curt <curty@free.fr> - 2024-03-29 18:50 +0100
Re: making Debian secure by default Nicholas Geovanis <nickgeovanis@gmail.com> - 2024-04-01 02:30 +0200
Re: making Debian secure by default Andy Smith <andy@strugglers.net> - 2024-04-01 03:50 +0200
Re: making Debian secure by default Roberto C. Sánchez <roberto@debian.org> - 2024-04-01 05:00 +0200
Re: making Debian secure by default Nate Bargmann <n0nb@n0nb.us> - 2024-04-01 10:40 +0200
Re: making Debian secure by default <tomas@tuxteam.de> - 2024-04-06 09:50 +0200
Re: making Debian secure by default Nate Bargmann <n0nb@n0nb.us> - 2024-04-06 09:50 +0200
Re: making Debian secure by default <tomas@tuxteam.de> - 2024-04-06 09:51 +0200
Re: making Debian secure by default <tomas@tuxteam.de> - 2024-04-06 09:50 +0200
Re: making Debian secure by default Andy Smith <andy@strugglers.net> - 2024-04-06 09:50 +0200
Re: making Debian secure by default Nate Bargmann <n0nb@n0nb.us> - 2024-04-06 09:51 +0200
Re: making Debian secure by default Andy Smith <andy@strugglers.net> - 2024-04-06 09:51 +0200
Re: making Debian secure by default Jeffrey Walton <noloader@gmail.com> - 2024-04-06 09:51 +0200
Re: making Debian secure by default Nate Bargmann <n0nb@n0nb.us> - 2024-04-06 09:52 +0200
Re: making Debian secure by default Charles Curley <charlescurley@charlescurley.com> - 2024-04-06 09:52 +0200
Re: making Debian secure by default Jeffrey Walton <noloader@gmail.com> - 2024-04-06 09:51 +0200
Re: making Debian secure by default John Hasler <john@sugarbit.com> - 2024-04-06 09:51 +0200
Re: making Debian secure by default Joe <joe@jretrading.com> - 2024-04-06 09:52 +0200
Re: making Debian secure by default John Hasler <john@sugarbit.com> - 2024-04-06 09:52 +0200
Re: making Debian secure by default Joe <joe@jretrading.com> - 2024-04-06 09:52 +0200
Re: making Debian secure by default Curt <curty@free.fr> - 2024-03-29 18:50 +0100
Re: making Debian secure by default Andy Smith <andy@strugglers.net> - 2024-03-29 21:00 +0100
Re: making Debian secure by default Curt <curty@free.fr> - 2024-03-30 17:10 +0100
Re: making Debian secure by default Lee <ler762@gmail.com> - 2024-03-28 19:10 +0100
Re: making Debian secure by default Jeffrey Walton <noloader@gmail.com> - 2024-03-28 23:20 +0100
Re: making Debian secure by default Florent Rougon <f.rougon@free.fr> - 2024-03-28 17:30 +0100
Re: making Debian secure by default Florent Rougon <f.rougon@free.fr> - 2024-03-28 18:10 +0100
Re: making Debian secure by default Greg Wooledge <greg@wooledge.org> - 2024-03-28 18:10 +0100
Re: making Debian secure by default Florent Rougon <f.rougon@free.fr> - 2024-03-28 18:10 +0100
Re: making Debian secure by default jeremy ardley <jeremy.ardley@gmail.com> - 2024-03-28 00:40 +0100
Re: making Debian secure by default Andy Smith <andy@strugglers.net> - 2024-03-28 00:50 +0100
Re: making Debian secure by default Lee <ler762@gmail.com> - 2024-03-28 05:50 +0100
Re: making Debian secure by default <tomas@tuxteam.de> - 2024-03-28 06:20 +0100
Re: making Debian secure by default Emanuel Berg <incal@dataswamp.org> - 2024-03-28 06:30 +0100
Re: making Debian secure by default <tomas@tuxteam.de> - 2024-03-28 08:20 +0100
Re: making Debian secure by default Michael Kjörling <2695bd53d63c@ewoof.net> - 2024-03-28 12:20 +0100
Re: making Debian secure by default Emanuel Berg <incal@dataswamp.org> - 2024-03-28 12:40 +0100
Re: making Debian secure by default David Wright <deblis@lionunicorn.co.uk> - 2024-03-28 21:40 +0100
Re: making Debian secure by default Emanuel Berg <incal@dataswamp.org> - 2024-03-29 10:40 +0100
Re: making Debian secure by default David Wright <deblis@lionunicorn.co.uk> - 2024-03-30 04:00 +0100
Re: making Debian secure by default Curt <curty@free.fr> - 2024-03-28 15:50 +0100
Re: making Debian secure by default Lee <ler762@gmail.com> - 2024-03-28 17:30 +0100
Re: making Debian secure by default Andy Smith <andy@strugglers.net> - 2024-03-28 18:10 +0100
Re: making Debian secure by default Lee <ler762@gmail.com> - 2024-03-28 21:50 +0100
Re: making Debian secure by default tomas@tuxteam.de - 2024-03-28 18:30 +0100
Re: making Debian secure by default Lee <ler762@gmail.com> - 2024-03-28 20:30 +0100
Re: making Debian secure by default Greg Wooledge <greg@wooledge.org> - 2024-03-28 20:30 +0100
Re: making Debian secure by default Michael Kjörling <2695bd53d63c@ewoof.net> - 2024-03-28 21:50 +0100
Re: making Debian secure by default tomas@tuxteam.de - 2024-03-28 21:20 +0100
Re: making Debian secure by default Curt <curty@free.fr> - 2024-03-29 17:10 +0100
Re: making Debian secure by default debian-user@howorth.org.uk - 2024-03-29 21:50 +0100
Re: making Debian secure by default debian-user@howorth.org.uk - 2024-03-28 22:50 +0100
Re: making Debian secure by default Marc SCHAEFER <schaefer@alphanet.ch> - 2024-03-28 12:10 +0100
Re: making Debian secure by default Franco Martelli <martellif67@gmail.com> - 2024-03-28 17:30 +0100
Re: making Debian secure by default Michel Verdier <mv524@free.fr> - 2024-03-28 17:30 +0100
Re: making Debian secure by default Andy Smith <andy@strugglers.net> - 2024-03-28 17:40 +0100
Re: making Debian secure by default Michael Kjörling <2695bd53d63c@ewoof.net> - 2024-03-28 21:50 +0100
Re: making Debian secure by default Richmond <dnomhcir@gmx.com> - 2024-03-28 21:50 +0100
Re: making Debian secure by default Jeffrey Walton <noloader@gmail.com> - 2024-03-29 16:40 +0100
Re: making Debian secure by default Andy Smith <andy@strugglers.net> - 2024-03-31 21:10 +0200
Re: making Debian secure by default Roberto C. Sánchez <roberto@debian.org> - 2024-03-31 21:30 +0200
Re: making Debian secure by default gene heskett <gheskett@shentel.net> - 2024-03-31 22:30 +0200
Re: making Debian secure by default Andy Smith <andy@strugglers.net> - 2024-03-31 23:20 +0200
Re: making Debian secure by default gene heskett <gheskett@shentel.net> - 2024-04-01 01:00 +0200
csiph-web