Re: Linux needs a security audit

Pierre-Elliott Bécue <[email protected]> Mon, 15 Sep 2025 15:31:41 +0200
Newsgroups gmane.linux.debian.user,gmane.linux.debian.devel.project,gmane.linux.debian.user.events-eu
Message-ID <[email protected]>
--=-=-=
Content-Type: text/plain
Content-Transfer-Encoding: quoted-printable

Hello,

Michael Paoli <[email protected]> wrote on 15/09/2025 at 01:20:23+=
0200:

> "extraordinary claims require extraordinary evidence".
> Please point to the evidence.
> Both Linux and Tor, OpenSource,
> and with source/version control and history, etc.
> So if they were compromised at any point, or even
> unintentional compromising bugs introduced, one should
> well be able to point that out, and when, and the responsible
> party that introduced such.
> While I'm sure there are entities that would wish to compromise
> Linux and/or Tor, actually doing so is quite non-trivial, given all the
> eyes on the code, various testing and monitoring, etc.  Even when a
> bad actor intentionally compromised xz, that was caught in relatively
> short order, and long before making it to any Debian stable release or th=
e like.
> May want to first look at simpler more probable explanations before presu=
ming
> the much less probable.  E.g. if you believe you were compromised, were y=
ou
> compromised via other simpler, easier means, e.g. somehow otherwise leaki=
ng
> your information/data - such as a compromised Tor entry relay, or many
> other possible
> means, which would be a much simpler and easier attack/compromise
> than what you claim.  There are many other possibilities,
> but that's just one that's far simpler and easier than what you're claimi=
ng.
>
> So, if you claim compromise of the code, point to the actual evidence,
> where exactly
> in the code is the compromise?  Otherwise you're making quite
> extraordinary claims,
> without the corresponding evidence to back those claims.
>
> And you're claiming both were compromised?  Really.  Sounds like
> conspiracy fodder without backing evidence.

I see these kind of mails as wasteful in terms of resources, I'd suggest
not to engage.

Bests,
=2D-=20
PEB

--=-=-=
Content-Type: application/pgp-signature; name="signature.asc"

-----BEGIN PGP SIGNATURE-----

iQJDBAEBCgAtFiEE5CQeth7uIW7ehIz87iFbn7jEWwsFAmjIFT0PHHBlYkBkZWJp
YW4ub3JnAAoJEO4hW5+4xFsLz0kP/1wCShnTHTcz6flcr5NfaVOeYQTV28CNaiZF
QpOEt/yT2rOkh9IrOEtsyjyP7sG8EQoZznfwE26o3txKK+/cPu0039HlDDjRH24j
VxuoQLR7mqjYNmn1FVDVcMcGwz9sAsnlvF+e7Kg4YAHSr+MxZxGvxtY1pDA+BeL6
SY0E2Nk/UfCwDGJjOx4U3KJnhJsUt8EjbdhrjPgs8YBQYe80yACTPguW83IkvGIt
xLMsrQU/MhnR3J/Lvw/RNx+i/pqixkXHBW2IABZ9A4rBqBInVf/G+7L6FtIaVMLm
eqq3i3k5RrcWOUS1qfI/Isx/iz1qFY9HaH0uZ4q0LGbzLUnjbyjwcCT0fDL34OmH
dJgbWReI+ScWshK76bcWfnX9D4FCFJJJqgg4+f4HQjQRtPpW/HThmNmxDw14m3hC
f0Lhx6RaqE8AHzgOPil6qnml6CTYqfcOWJKOzdRYJow5TGbLBmvv/aogWAQ+FUHB
+CSA625MnE+MtKpnHoGVIiWldoq3bxa9QDGuCs0rQtEBp5+FwEdjfeVF+C9KazyV
PUubivTYVy0aMPp7WzGiwoZrsknzpIQtW7ABW62twY5s2H5W8rAVQ3/Jku+brE9F
ASm2lgBfyFh3rQANNMh48cyAkQid/B2S5Hb16x6WNpG53RrmWIfHn1NqaUESWz/C
nWD9O+RB
=/+tu
-----END PGP SIGNATURE-----
--=-=-=--