| ▲ | anonreplier a day ago | |
"all that telemetry" doesn't count for much if it's behind a VPN | ||
| ▲ | lucasRW an hour ago | parent [-] | |
Highly debatable. Threat-hunting at that level can easily use VPNs to make attributions, especially if those same VPN exit points happen to be correlated to other stuff that was attributed. And when you are Microsoft or Google (Jia Tan had gmail accounts), the telemetry they have goes way beyond "oh we can't see the real IP lolz". The group responsible for the xz attempted compromise is circulating in certain Chatham House rules conference. It's just that, as someone there said "no one has had the balls to say it publicly", which in itself gives a strong hint. | ||