TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

A stealth attack came close to compromising the Internet

27 点作者 wjb3大约 1 年前

8 条评论

cvoss大约 1 年前
While the article does present both sides of the classic open source debate (&quot;It&#x27;s vulnerable because it&#x27;s open&quot; vs. &quot;It&#x27;s safe because so many eyes are on it&quot;), it seems to come down on the side of the former. Typical non-software-engineering readers may take away the notion that they should trust open source software less, try to not to rely on it, and become frustrated by the realization that that&#x27;s almost entirely out of their control as a layperson. But typical software-engineering readers should take away the notion that they, too, should trust open source software less, and, as a solution, rather than withdraw from it, they should become more invested in its thesis of security through the wisdom of crowds.<p>The article quotes someone pooh-poohing &quot;hobbyist&quot; maintainers. But just because something is your hobby doesn&#x27;t mean you&#x27;re not a professional at it. Just because you don&#x27;t get paid for it doesn&#x27;t mean it&#x27;s not an incredibly valuable part of your contribution to the good of your neighbors. Keep up the excellent work, everyone.<p>I hope the xz lesson is one that moves us toward the ideal of open source, not away from it.
评论 #39948595 未加载
评论 #39948756 未加载
评论 #39948728 未加载
评论 #39948523 未加载
评论 #39949258 未加载
xyst大约 1 年前
I would say the quality of this article is a bit lacking. Offers absolutely nothing new other than speculation from a “widely read” cybersecurity researcher speculating about it being a Russian op.<p>If the original maintainer can work with LEOs, “jia tan” may have left some clues in the “off list” communications. Maybe headers off original emails show a pattern.<p>Maybe even coordinate with Google since the attackers used Gmail accounts. Quite possible an attacker accidentally logged in from a non-sanctioned device or sent email from non state owned device.<p>We are human after all and can make mistakes. Just as the attacker(s) got clumsy towards the end due to patching out loading of unnecessary libraries in systemd
评论 #39948668 未加载
mypastself大约 1 年前
Can’t wait for the inevitable book on this topic a few years from now, or at least a Darknet Diaries episode before that.<p>I do wonder when they’ll settle on a likely culprit. A few hours ahead of GMT and doesn’t work on Eastern European holidays? There’s probably more work to be done, but just going by the commit history, surely there’s a way to make a more granular assumption, because not all of those countries share all of the same holidays…
wjb3大约 1 年前
<a href="https:&#x2F;&#x2F;finance.yahoo.com&#x2F;news&#x2F;1-why-near-miss-cyberattack-151035964.html" rel="nofollow">https:&#x2F;&#x2F;finance.yahoo.com&#x2F;news&#x2F;1-why-near-miss-cyberattack-1...</a>
wolverine876大约 1 年前
Another way to look at it is as part of a major, unremarked change in society:<p>A couple years ago I was talking to someone who came of age since 2016, when I think many of these changes began moving rapidly. When I said something about a community project, they ridiculed the idea that people could and would come together and do good, productive things. I used FOSS as an example, and also of course, democracy.<p>The lack of social trust is a well-known concept, but I don&#x27;t know if people see the massive change where instead of defaulting to trust, the default is paranoia and also being distrustful - scamming others (&#x27;animal spirits&#x27;, as Jamie Dimon calls them). It&#x27;s also ridiculing, like my friend, the idea of democracy - for example, the popular notion that doing anything to stand up to power, especially organized protests, is pointless. The briefest glance at history shows otherwise, but of course fact &amp; reason are not the mode of analysis these days. <i>Cui bono?</i> People who have capital and power; people who want to take down the power of the people and democracy.<p>If you look at FOSS from the usual humanistic democratic perspective, with social trust (which is part of human nature, despite attempts to destroy it) - that free people generally do good and well and can self-organize, and that now the Internet provides a way for them to do all that easily - then these big coordinated FOSS projects are a happy thing and make sense.<p>But if you look at it from the current madness, the paranoia and hate, then FOSS becomes suspect. Without social trust, how could such an organization work? Only an organization controlled by a powerful person could acheives something. Think about it: why is the latter type of organization more likely to work than the former?
xyst大约 1 年前
non-paywall: <a href="https:&#x2F;&#x2F;archive.is&#x2F;CbRJT" rel="nofollow">https:&#x2F;&#x2F;archive.is&#x2F;CbRJT</a>
评论 #39948513 未加载
wjb3大约 1 年前
&quot;This is the Silver Back Gorilla of nerds. The internet final boss.&quot; <a href="https:&#x2F;&#x2F;twitter.com&#x2F;vxunderground&#x2F;status&#x2F;1774071339671794134" rel="nofollow">https:&#x2F;&#x2F;twitter.com&#x2F;vxunderground&#x2F;status&#x2F;1774071339671794134</a>
评论 #39948364 未加载
评论 #39948420 未加载
johnea大约 1 年前
Typical economist.com view on the world: &quot;This could have been a problem for the world&#x27;s wealthy!!!&quot;<p>Not that they would ever agreee to any kind of shared support for the free s&#x2F;w projects that today&#x27;s internet depends on, because... Elon needs more.<p>Also, I would argue, a good reasson not to be an update apostle.<p>Disable automatic updates, update when you need an updated version of something, or a new vuln directly affects your usage model, not just because an update is available...
评论 #39948423 未加载