oss-sec mailing list archives
Re: backdoor in upstream xz/liblzma leading to ssh server compromise
From: Tavis Ormandy <taviso () gmail com>
Date: Fri, 29 Mar 2024 21:54:11 -0000 (UTC)
On 2024-03-29, Solar Designer wrote:
I have a minor procedural question for Solar though, shouldn't this have been redirected to oss-security immediately from distros? What's the rationale for an embargo here?We don't have a clear policy for such case. Some distros list members have indeed suggested making this public ASAP. We ended up delaying publication by one day per my suggestion (as a compromise between ASAP and having no specific CRD), and I think these are some reasons why:
Thanks, a compromise is better than nothing :) I think I would have argued for immediately discussing this in the open.
If this were made public yesterday, there would be more of a panic.
There are lots of actions possible without any official guidance from vendors, and sometimes hours can make a difference. I don't think it's fair to characterize that as panic.
2. We didn't know how the culprit (or group) would react when they learned of the full extent of the community's awareness.
This is true with any vulnerability, there is always the possibility an attacker is already aware of it. They could respond to a patch being released by trying to extract as much value from their exploit before it's worthless. I'm not convinced that's a good argument to delay making the patch available?
3. We were aware of concurrent coordination efforts by other groups (CERT/CC, CISA) and we didn't want to interfere with their plans.
The trade-off here is we're delaying everybody elses ability to react. I worry they might want a delay to patch the systems they care about first. Perhaps if a representative had said the feds request a few hours because they're deploying a helicopter full of agents to make an arrest, well okay, that's more convincing :)
4. More findings were still being made and the wording of Andres' posting improved per private feedback.
Sure, but this could have been done in the open on oss-security, right? Tavis. -- _o) $ lynx lock.cmpxchg8b.com /\\ _o) _o) $ finger taviso () sdf org _\_V _( ) _( ) @taviso
Current thread:
- Re: backdoor in upstream xz/liblzma leading to ssh server compromise, (continued)
- Re: backdoor in upstream xz/liblzma leading to ssh server compromise Solar Designer (Mar 29)
- Re: backdoor in upstream xz/liblzma leading to ssh server compromise Solar Designer (Mar 31)
- Re: backdoor in upstream xz/liblzma leading to ssh server compromise Michael Tokarev (Mar 31)
- Re: backdoor in upstream xz/liblzma leading to ssh server compromise Rein Fernhout (Levitating) (Mar 29)
- Re: backdoor in upstream xz/liblzma leading to ssh server compromise Andres Freund (Mar 29)
- Re: backdoor in upstream xz/liblzma leading to ssh server compromise Rein Fernhout (Levitating) (Mar 30)
- Re: backdoor in upstream xz/liblzma leading to ssh server compromise Matthias Weckbecker (Mar 30)
- Re: backdoor in upstream xz/liblzma leading to ssh server compromise Solar Designer (Mar 29)
- Re: backdoor in upstream xz/liblzma leading to ssh server compromise Andres Freund (Mar 29)
- Re: backdoor in upstream xz/liblzma leading to ssh server compromise Tavis Ormandy (Mar 29)
- Re: Re: backdoor in upstream xz/liblzma leading to ssh server compromise Andres Freund (Mar 29)
- Re: backdoor in upstream xz/liblzma leading to ssh server compromise Tavis Ormandy (Mar 29)
- Re: Re: backdoor in upstream xz/liblzma leading to ssh server compromise Liguori, Anthony (Mar 29)
- Re: Re: backdoor in upstream xz/liblzma leading to ssh server compromise Marc Deslauriers (Mar 29)
- Re: Re: backdoor in upstream xz/liblzma leading to ssh server compromise Russ Allbery (Mar 29)
- Re: Re: backdoor in upstream xz/liblzma leading to ssh server compromise Marc Deslauriers (Mar 29)
- Re: backdoor in upstream xz/liblzma leading to ssh server compromise Tavis Ormandy (Mar 29)
- Re: Re: backdoor in upstream xz/liblzma leading to ssh server compromise Marc Deslauriers (Mar 29)
- Re: backdoor in upstream xz/liblzma leading to ssh server compromise Tavis Ormandy (Mar 30)
- Re: Re: backdoor in upstream xz/liblzma leading to ssh server compromise Marc Deslauriers (Mar 30)