• Anna@lemmy.ml
    link
    fedilink
    arrow-up
    23
    ·
    3 days ago

    Hey we need people like that, remember when an autistic person discovered few hundred millisecond delay in ssh which uncovered Jia Tan backdoor.

      • Anna@lemmy.ml
        link
        fedilink
        arrow-up
        2
        ·
        edit-2
        15 hours ago

        This is the original email by the person who discovered this backdoor. But if you want you can search for xz backdoor and you’ll find a lot more articles which explain timelines and other things. https://www.openwall.com/lists/oss-security/2024/03/29/4

         == Observing Impact on openssh server ==
        
        With the backdoored liblzma installed, logins via ssh become a lot slower.
        
        time ssh nonexistant@...alhost
        
        before:
        nonexistant@...alhost: Permission denied (publickey).
        
        before:
        real	0m0.299s
        user	0m0.202s
        sys	0m0.006s
        
        after:
        nonexistant@...alhost: Permission denied (publickey).
        
        real	0m0.807s
        user	0m0.202s
        sys	0m0.006s
        

        That’s a 500ms or 0.5s difference