Hacker News new | past | comments | ask | show | jobs | submit login

That nobody is talking about the person's IP addresses (the xz project was hosted on a personal server of the maintainer), or any details about their actions indicates to me it was a state actor and the original xz maintainer is cooperating with law enforcement to uncover their actions.



Based on working hours Israeli is likely

https://rheaeve.substack.com/p/xz-backdoor-times-damned-time...

There are other countries on the same time zone, but only Israel has history of using and selling hacks of this level.


Or someone further west who did this after work during the evenings.

Or someone further east with a classical hacker "let's get up late in the afternoon, and start the serious hacking late at night."


From that article, "To further investigate, we can try to see if he worked on weekends or weekdays: was this a hobbyist or was he paid to do this? The most common working days for Jia were Tue (86), Wed (85), Thu (89), and Fri (79)." That makes it more likely this work was done during working hours; someone doing things outside of work hours would be more likely to produce the same amount (or more) on weekends and holidays.


Yes, that would point towards regular office hours and not hacking hours.


Moscow is the same time zone as Israel.


Whilst the ip addresses and email headers etc should be examined meticulously, in the distant hope that they lead somewhere, the chances are that they won't. Very basic opsec.


I thought it was on GitHub pages?


Before pages the project was hosted on the server of the original maintainer.


CISA is investigating it.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: