Remix.run Logo
lucasRW a day ago

It's only going to recycle old news. The missing piece is attribution. Had it been the usuals (DPRK, Russia, China), the attribution would have been made publicly. The fact that is has not points as a friendly - especially when Microsoft (who owns Github) had all that telemetry and very likely has the means to find out. Some serious OSINT (consistency of timezone across months if not years of commits) pointed to the Middle East. An obvious Unit name comes to mind.

diogocp a day ago | parent | next [-]

Fun fact: the guy who reported it (Andres Freund) works for Microsoft.

Another fun fact: Moscow is in the same time zone as the Middle East.

kryogen1c a day ago | parent | next [-]

The middle east is not one time zone

https://whichtimezone.com/me/middle-east-map/

lucasRW 2 hours ago | parent [-]

I know.

lucasRW a day ago | parent | prev [-]

Other fun fact: Microsoft and Mandiant have never had any problem doxing Russian APTs when they caught them.

anonreplier a day ago | parent | prev [-]

"all that telemetry" doesn't count for much if it's behind a VPN

lucasRW 2 hours ago | parent [-]

Highly debatable.

Threat-hunting at that level can easily use VPNs to make attributions, especially if those same VPN exit points happen to be correlated to other stuff that was attributed. And when you are Microsoft or Google (Jia Tan had gmail accounts), the telemetry they have goes way beyond "oh we can't see the real IP lolz".

The group responsible for the xz attempted compromise is circulating in certain Chatham House rules conference. It's just that, as someone there said "no one has had the balls to say it publicly", which in itself gives a strong hint.