Skip to content

Comment on Half a Second – a book about the XZ backdoorparent

Comments

Highly debatable.

Threat-hunting at that level can easily use VPNs to make attributions, especially if those same VPN exit points happen to be correlated to other stuff that was attributed. And when you are Microsoft or Google (Jia Tan had gmail accounts), the telemetry they have goes way beyond "oh we can't see the real IP lolz".

The group responsible for the xz attempted compromise is circulating in certain Chatham House rules conference. It's just that, as someone there said "no one has had the balls to say it publicly", which in itself gives a strong hint.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.