Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

The discussion to upload it to Debian is interesting on its own https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1067708


Wow, that's a lot of anonymous accounts adding comments there urging for a fast merge!

And this "Hans Jansen" guy is apparently running around salsa.debian.org pushing for more updates in other projects as well: https://salsa.debian.org/users/hjansen/activity


>that's a lot of anonymous accounts

Just FYI, krygorin4545@proton.me (the latest message before the upload) was created Tue Mar 26 18:30:02 UTC 2024, about an hour earlier than the message was posted.

Proton generates PGP key upon creating the account, with the real datetime of the key (but the key does not include the timezone).


> running around salsa.debian.org pushing for more updates in other projects as well

This is quite common in most (all?) distributions. People are going through lists of outdated packages, updating them, testing them, and pushing them.


That account seems to be a contributor for xz though, you can see him interact a lot with the author of the backdoor on the GitHub repo. Some pull requests seem to be just the two of them discussing and merging stuff (which is normal but looks weird in this context)


And now we see why I don't trust anons, aliases, or anime characters to make contributions.

My GitHub says exactly who I am!


Even if they have a "real" picture or a credible description that is not good enough. Instead of using an anime character a malicious actor could use an image generator [0], they could generate a few images, obtain something credible to most folks, and use that to get a few fake identities going. Sadly, trusting people to be the real thing and not a fake identity on the Internet is difficult now and it will get worse.

[0] https://thispersondoesnotexist.com


You can quite easily generate a realistic photo, bio, even entire personal blogs and GitHub projects, using generative AI, to make it look like it's a real person.


With close to zero OSS participation rate you can just pick a real living person and just keep in sync with their LinkedIn.


It has been on the agenda for years to identify FOSS contributors with an id… Wet dream for authoritarians like you.

What would it solve when identity theft happens on a mass scale on a day to day basis?

It'd just ruin the life of some random person whose identity got stolen to create the account…


That name jumped out at me, Hans Jansen is the name Dominic Monaghan used when posing as a German interviewer with Elijah Woods. Not that it can't be a real person

https://youtu.be/IfhMILe8C84


Hans Gruber would have Been a much more stylish choice…


See comments about "Hans Janson" upthread, he appeared to collaborate on the exploit in other ways as well.


For anyone else feeling some deja vu about ifunc / Valgrind errors, this Red Hat issue [1] was previously linked from HN 12 days ago [2].

[1]: https://bugzilla.redhat.com/show_bug.cgi?id=2267598

[2]: https://news.ycombinator.com/item?id=39733185


I get the feeling that a number of the comments are all the same person / group.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: