logo
episode-header-image
Aug 2024
44 m

SE Radio 630: Luis Rodríguez on the SSH ...

se-radio@computer.org
About this episode

Luis Rodríguez, CTO of Xygeni.io, joins host Robert Blumen for a discussion of the recently thwarted attempt to insert a backdoor in the SSH (Secure Shell) daemon. OpenSSH is a popular implementation of the protocol used in major Linux distributions for authentication over a network. Luis describes how a backdoor in a supporting library was recently discovered and removed before the package was published to stable releases of the Linux distros. The conversation explores the mechanism of the attack through modifying a function table in the runtime; how the attack was inserted during the build; how the attack was carefully staged in a series of modifications to the lz compression library; the nature of "Jia Tan," the entity who committed the changes to the open source project; social engineering that the entity used to gain the trust of the open source community; what forensics indicates about the location of the entity; hypotheses about whether criminal or state actors backed the entity; how the attack was detected; implications for other open source projects; why traditional methods for detecting exploits would not have helped find this; and lessons learned by the community.

Brought to you by IEEE Computer Society and IEEE Software magazine.

Up next
Apr 23
SE Radio 717: Eric Tschetter on Decoupling Observability
In this episode, host Amey Ambade sits with Eric Tschetter, co-founder of Apache Druid and Chief Architect at Imply, to dissect the critical move toward Decoupling Observability. To begin, they define three pillars—logs, metrics, and traces—and consider why the rise of microservi ... Show More
1 h
Apr 15
SE Radio 716: Martin Kleppmann Local-First Software
Martin Kleppmann, Associate Professor at the University of Cambridge and author of the best-selling O'Reilly book Designing Data-Intensive Applications, talks to host Adi Narayan about local-first collaboration software. They discuss what the term means, how it leads to simpler a ... Show More
55m 14s
Apr 8
SE Radio 715: Sahaj Garg on Designing for Ambiguity in Human Input
Sahaj Garg, co-founder and CTO of Wispr, a voice-to-text AI that turns speech into polished writing, talks with host Amey Ambade about designing systems for the ambiguity that's inherent in human input (text, voice, multimodal). Sahaj focuses on concrete architectural and trainin ... Show More
48m 2s
Recommended Episodes
Jan 2025
Crypto client or cyber trap? [Research Saturday]
Karlo Zanki, Reverse Engineer at ReversingLabs, discussing their work on "Malicious PyPI crypto pay package aiocpa implants infostealer code." ReversingLabs' machine learning-based threat hunting system identified a malicious PyPI package, aiocpa, designed to exfiltrate cryptocur ... Show More
21m 2s
Oct 2025
Inside the Linux Foundation's Open-Source Movement
Daniela Barbosa, General Manager of Decentralized Technologies at the Linux Foundation, and Executive Director at LF Decentralized Trust, discusses the most promising open-source projects they've supported so far, and how more builders can get involved. She also emphasizes the im ... Show More
24m 34s
Oct 2025
Zero Day, Zero Warning: Inside the Discovery That Could Have Crippled the Internet
<p>Twelve years. That's how long a vulnerability sat in sudo—the command powering every Linux system—waiting for the wrong hands. When Stratascale researchers Rich Mirch and Quentin Rhoads-Herrera discovered not one, but two zero-day vulnerabilities in sudo, millions of systems w ... Show More
35m 54s
Jun 2025
Hiding in plain sight with vibe coding.
This week, Dave is joined by ⁠Ziv Karliner⁠, ⁠Pillar Security⁠’s Co-Founder and CTO, sharing details on their work on "New Vulnerability in GitHub Copilot and Cursor: How Hackers Can Weaponize Code Agents." Vibe Coding - where developers use AI assistants like GitHub Copilot and ... Show More
21m 49s
Aug 2024
Cyber revolt or just digital ruckus?
Hacktivists respond to the arrest of Telegram’s CEO in France. Stealthy Linux malware stayed undetected for two years. Versa Networks patches a zero-day vulnerability. Google has patched its tenth zero-day vulnerability of 2024. Researchers at Arkose labs document Greasy Opal. A ... Show More
25m 20s
Apr 2025
146: When AI Attacks
We're joined by Xe Iaso, who discusses a creative solution to relentless AI bots and the unexpected delights of running an outrageously overpowered homelab. Special Guest: Xe Iaso. 
47m 30s