Hacker News new | past | comments | ask | show | jobs | submit login

I agree, but the social engineering parts do feel particularly cruel



I felt really bad for the original maintainer getting dog-piled by people who berated him for not doing his (unpaid) job and basically just bring shame and discredit to himself and the community. Definitely cruel.

Though… do we know that the maintainer at that point was the same individual as the one who started the project? Goes deep, man.


Its possible the adversary was behind or at least encouraged the dog piling who berated him. Probably a normal basic tactic from a funded evil team playbook.

Might be worth reviewing those who berated him to see if they resolve to real people, to see how deep this operation goes.


This has been investigated and the conclusion is IMO clear: the dogpilling accounts were part of the operation. See the parts about Jigar Kumar in this link: https://boehs.org/node/everything-i-know-about-the-xz-backdo...


One of them who left only one comment does, the rest are sock puppets.


Even if it's not his fault the maintainer at this point won't be trusted at all. I feel for him, I think even finding a job at this moment for him would be impossible. Why would you hire someone that could be suspected for that?


No. From what I've read on the openwall and lkml mailing lists (so generally people who know a lot more about these things than I do), nobody accused Lasse Collins, the original maintainer, of being involved in this, at all, and there wasn't any notion of him becoming untrustworthy.


This could've happened to anybody, frankly. The attacker was advanced and persistent. I cannot help but feel sympathetic for the original maintainer here.


From TFA's profile:

https://bsky.app/profile/filippo.abyssdomain.expert/post/3ko...

This is a profound realization, isn't it? How much more paranoid should/will maintainers be going forward?




Consider applying for YC's Spring batch! Applications are open till Feb 11.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: