Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Excellent summary of the events, with all the links in one place. This is the perfect resource for anyone who want to catch up, and also to learn about how such things (especially social engineering) unfold in the wild, out in the open.

One thing that could be added, for the sake of completeness: in the part "Attack begins", toward the end, when they are pushing for updating xz in the major distros, Ubuntu and Debian are mentioned but not Fedora.

Looks like the social engineering/pressuring for Fedora started at least weeks before 2024 March 04, according to a comment by @rwmj on HN [1]. I also found this thread on Fedora's devel list [2], but didn't dig too much.

[1] https://news.ycombinator.com/item?id=39866275

[2] https://lists.fedoraproject.org/archives/list/devel@lists.fe...



It would be intetesting if Lasse Collin published his off-list interactions with 'Jia Tan' and any of the other pseudonyms, to get an even better angle on the social engineering parts. Apparently a large part of the campaign was via private channels to Lasse.


Collin has been writing more extensively on IRC. A screenshot of one of his posts can be seen in [this YouTube video](https://youtu.be/0pT-dWpmwhA?t=1158).

He notes that while he was unsatisfied with some of the changes Tan introduced, Tan was nonetheless extremely helpful.


> [...] unsatisfied with some of the changes Tan introduced [...]

That's one way to put it


I was wondering if that would be released also. I hope so but wouldn't blame them if they decide not to.


I wouldn't blame then if they've thrown all their computers into the sea, changed their name, and taken upon a job building timber furniture...


I, too, have had days like that


as an alaskan, those aren't mutually exclusive




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: