Re: [oss-security] Analysis on who is Jia Tan, and who he could work for, reading xz.git

2024-04-12 Thread Alejandro Colomar
Hi Jacob, Thanks to your script, I've found a mistake in my analysis of the timestamps. The commit dates in +0200 recently seem to be because Jia Tan rebased some commits from Lasse, and used --committer-date-is-author-date. commit 3007e74ef250f0ce95d97ffbdf2282284f93764d Author:

Re: [oss-security] Analysis on who is Jia Tan, and who he could work for, reading xz.git

2024-04-11 Thread Alejandro Colomar
Hi Jacob, [reordered] > Lastly, I believe that if (a big "if") enough evidence can be found to make > attribution of the xz backdoor stick, the results are likely to be a > political scandal that will serve to deter others from similarly going > rogue, so pinning the "Jia" on the sockmaster might