Close Menu

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Please enable JavaScript in your browser to complete this form.
    Loading
    What's Hot

    Get 1 Year of The Zero Byte for $30: Lawsuit Highlights Fake News

    October 21, 2024

    Get One Year of The Zero Byte for $5: How a Trump Win Could Unleash AI

    October 21, 2024

    Get One Year of The Zero Byte for $5: Sam Altman’s Eye-Scanning Orb Delivered

    October 17, 2024
    Facebook X (Twitter) Instagram
    The Zero ByteThe Zero Byte
    • AI
    • Tech
      1. Computing
      2. Cybersecurity
      3. Politics
      4. Smart Home
      5. Software
      6. Startups
      7. Streaming Services
      8. Virtual Reality
      9. View All

      OpenAI Unveils New AI Safety Research, Critics Call for More Action

      July 17, 2024

      Samsung Galaxy Book 4 Edge is among the first Copilot+ PCs to arrive

      June 20, 2024

      M4 MacBook Pros Expected to Launch in Late 2024

      June 19, 2024

      AI Cameras on UK Trains Use Amazon Tech to Monitor Passenger Emotions

      June 17, 2024

      Can You Trust ChatGPT-4o With Your Private Data?

      July 31, 2024

      ACLU Defends Your Right to Create Deepfakes

      July 24, 2024

      Apple, Nvidia, Anthropic Used YouTube Videos to Train AI

      July 16, 2024

      AI Spam Outranks Original News in Google Search Results

      July 2, 2024

      New Jersey’s $500M Plan to Lead in AI Innovation

      July 25, 2024

      ACLU Defends Your Right to Create Deepfakes

      July 24, 2024

      French AI Startups Thrived Until the Election Changed Everything

      June 28, 2024

      Auto Industry Calls Biden’s New Automatic Braking Rule “Impractical

      June 24, 2024

      Why Heat Pumps Are Gaining Popularity

      May 23, 2024

      Green and Blue-Green Roofs: The Ultimate Eco-Friendly Solution

      April 22, 2024

      Couple’s Journey to Eliminate Natural Gas from Their Home

      March 30, 2024

      Zoom Challenges Google and Microsoft with AI-Powered Documents

      August 6, 2024

      Download Paywalled Articles Easily with Quora’s Poe Chatbot Platform

      June 28, 2024

      Apple WWDC 2024 Live Blog: Major AI, iOS, and Software Updates Expected

      June 10, 2024

      Lightroom’s AI Tool Quickly Removes Unwanted Objects

      May 21, 2024

      Anthropic Unveils Method to Understand AI’s Inner Workings

      May 21, 2024

      OpenAI Dissolves Long-Term AI Risk Team Amid Growing Concerns

      May 17, 2024

      VSCO Launches Marketplace Connecting Photographers and Brands

      May 7, 2024

      Quora CEO Discusses AI, Poe Chatbot, and OpenAI’s Non-Competitive Role

      May 6, 2024

      Get One Year of The Zero Byte for Just $5

      September 26, 2024

      Spotify Expands Enterprise and Developer Tools with Backstage Platform

      April 30, 2024

      Rio: The AI News Anchor App Secures Funding from Curio

      April 26, 2024

      Substack Enhances Notes Feature with Twitter-Inspired Functionalities

      April 16, 2024

      Saga’s HoloBike: A Bizarre Virtual Reality Cycling Experience

      May 7, 2024

      Exploring the World Beyond Apple’s Vision Pro Headset

      April 20, 2024

      Disney Imagineer Builds Real-Life Lightsaber: Bringing Star Wars to Life

      April 8, 2024

      Apple’s Vision Pro Aims to Solve VR’s Biggest Problems: Comfort and Immersion

      April 8, 2024

      Get One Year of The Zero Byte for Just $5

      September 26, 2024

      Get One Year of The Zero Byte for Just $5

      September 25, 2024

      Get One Year of The Zero Byte for Just $30

      September 18, 2024

      AI Scientist Invents and Runs Its Own Experiments

      August 21, 2024
    • Gaming
      1. Gaming Hardware
      2. Game Reviews
      3. View All

      Game Devs at GDC Demand Change Amidst Internet Outrage

      March 26, 2024

      Retro Oddities: A Must-Own Gaming History Lesson in The Zero Byte Collection

      March 14, 2024

      Snag a PS5 Bundle with Marvel’s Spider-Man 2 for Just $399.99 Today

      March 11, 2024

      MSI Claw: A Formidable Challenger to the Steam Deck

      March 11, 2024

      Sonic Heroes Rumored to Make a Comeback: What We Know

      March 26, 2024

      Game Devs at GDC Demand Change Amidst Internet Outrage

      March 26, 2024

      Rise of the Ronin’s Innovative Feature: A New Industry Standard

      March 24, 2024

      Rise of the Ronin: A Masterful Blend of Gaming’s Finest Elements

      March 13, 2024

      Video Game Actors Strike Over AI Concerns

      July 25, 2024

      Carv Secures $10M Series A to Empower Gamers to Monetize Their Data

      April 25, 2024

      Raichu Mega Evolution Forms Imagined by Creative Pokemon Fan

      March 26, 2024

      Sonic Heroes Rumored to Make a Comeback: What We Know

      March 26, 2024
    • Gadgets
      1. New Gadgets
      2. Phones and Tech
      3. Wearables
      4. Gadget Reviews
      5. View All

      Acer Chromebook Plus: The Perfect Student Laptop Solution

      April 18, 2024

      OnePlus Unveils Its Own Take on Google’s Magic Eraser Feature

      April 3, 2024

      Do Smartphones Help or Harm Kids? Exploring the Pros and Cons

      March 29, 2024

      Google to Introduce AI-Powered Features on Pixel 8 Devices

      March 28, 2024

      Humane Ai Pin: A Flawed Glimpse into the Future of Wearable Tech

      April 11, 2024

      Withings ScanWatch 2 and Light: Effortless Elegance for the Tech-Weary

      March 11, 2024

      Acer Chromebook Plus: The Perfect Student Laptop Solution

      April 18, 2024

      AMD 3D V-Cache Processor to Avoid: The Zero Byte’s Recommendation

      March 26, 2024

      Microsoft Unveils Unexpected Surface Devices in Latest Launch

      March 22, 2024

      OnePlus 12 Screen: Is It Curved or Flat? Here’s What We Know

      March 16, 2024

      Top 9 TV Streaming Devices for 4K and HD: Our Best Picks

      June 19, 2024

      M4 MacBook Pros Expected to Launch in Late 2024

      June 19, 2024

      McLaren Artura Spider Hybrid: High Performance and Fun

      June 16, 2024

      Apple AI May Not Work on Millions of iPhones—But There’s Hope

      June 17, 2024
    • Science
      1. Health
      2. Space
      3. Psychology and Neuroscience
      4. Robots
      5. Space
      6. View All

      New Alzheimer’s Treatments Useless Without Early Diagnosis

      June 24, 2024

      Post-Pandemic Recovery: Challenges and Uncertainties Ahead

      June 24, 2024

      How to Exercise Safely During a Heat Wave

      June 22, 2024

      Tips to Stay Healthy and Avoid Illness This Summer

      June 15, 2024

      NASA Investigates Starliner Faults, Indefinite Delay in Space

      June 23, 2024

      What Happened Before the Big Bang?

      June 23, 2024

      SpaceX Starship Test Brings Mars Mission Closer

      June 6, 2024

      Searching for Ultralight Dark Matter Explained

      June 2, 2024

      Get One Year of The Zero Byte for $5: Most US Teens Use AI, Parents Unaware

      September 18, 2024

      New Alzheimer’s Treatments Useless Without Early Diagnosis

      June 24, 2024

      Arctic Zombie Fire Season Begins: What You Need to Know

      June 1, 2024

      Can AI Prove String Theory’s Accuracy in Describing Our World?

      May 26, 2024

      AI Scientist Invents and Runs Its Own Experiments

      August 21, 2024

      Boeing’s Starliner Set to Launch NASA Astronauts After Delays

      May 6, 2024

      SpaceX’s Starship: The Future Plans and Upcoming Developments

      March 15, 2024

      Uncanny Valley: Exploring the Realm of Eerie AI Dolls

      March 13, 2024

      NASA Investigates Starliner Faults, Indefinite Delay in Space

      June 23, 2024

      What Happened Before the Big Bang?

      June 23, 2024

      SpaceX Starship Test Brings Mars Mission Closer

      June 6, 2024

      Searching for Ultralight Dark Matter Explained

      June 2, 2024

      Get One Year of The Zero Byte for $5: Most US Teens Use AI, Parents Unaware

      September 18, 2024

      AI Scientist Invents and Runs Its Own Experiments

      August 21, 2024

      New Alzheimer’s Treatments Useless Without Early Diagnosis

      June 24, 2024

      Post-Pandemic Recovery: Challenges and Uncertainties Ahead

      June 24, 2024
    • Movies
      • Movie Reviews
    • Auto
    • Reviews
      1. Gadget Reviews
      2. Game Reviews
      3. Movie Reviews
      4. View All

      Acer Chromebook Plus: The Perfect Student Laptop Solution

      April 18, 2024

      AMD 3D V-Cache Processor to Avoid: The Zero Byte’s Recommendation

      March 26, 2024

      Microsoft Unveils Unexpected Surface Devices in Latest Launch

      March 22, 2024

      OnePlus 12 Screen: Is It Curved or Flat? Here’s What We Know

      March 16, 2024

      Sonic Heroes Rumored to Make a Comeback: What We Know

      March 26, 2024

      Game Devs at GDC Demand Change Amidst Internet Outrage

      March 26, 2024

      Rise of the Ronin’s Innovative Feature: A New Industry Standard

      March 24, 2024

      Rise of the Ronin: A Masterful Blend of Gaming’s Finest Elements

      March 13, 2024

      Oscars 2024: Unveiling the Triumphs and Surprises in Cinema

      March 11, 2024

      Conann: A Glamorous Fever Dream Exploring Beauty in Barbarism

      March 12, 2024

      Acer Chromebook Plus: The Perfect Student Laptop Solution

      April 18, 2024

      Sonic Heroes Rumored to Make a Comeback: What We Know

      March 26, 2024

      Game Devs at GDC Demand Change Amidst Internet Outrage

      March 26, 2024

      Rise of the Ronin’s Innovative Feature: A New Industry Standard

      March 24, 2024
    The Zero ByteThe Zero Byte
    Home»AI»Unmasking ‘Jia Tan’: The Enigmatic XZ Backdoor Mastermind
    Unmasking ‘Jia Tan’: The Enigmatic XZ Backdoor Mastermind
    AI

    Unmasking ‘Jia Tan’: The Enigmatic XZ Backdoor Mastermind

    By TZBApril 3, 20243 Mins Read
    Share
    Facebook Twitter Copy Link

    The Enigmatic Jia Tan:‌ A Mastermind‍ Behind XZ ​Utils Sabotage

    According to Scott, the three years ​Jia Tan spent making code changes ​and sending polite emails were‍ likely not a mere‌ act of sabotage targeting multiple software projects. Instead, it appears to ⁣be​ a calculated effort to establish credibility before ‍specifically targeting XZ Utils and potentially other ​projects in the future. “We were ‌fortunate to discover his activities before​ he ‍could proceed to the next stage,”⁣ Scott⁢ remarks. “His cover is‍ now blown,⁤ and he’ll‍ have to start⁤ from scratch.”

    Unveiling the Techniques ‌and Origins of the Backdoor

    Sophisticated Code and Passive⁢ Backdoor

    Costin ​Raiu, a⁤ former lead researcher at​ Kaspersky, points out that the malicious code added by Jia Tan to XZ Utils bears the hallmarks of a ⁣well-organized, state-sponsored hacker group, despite the persona’s appearance as an individual. The code, at first glance, ‍resembles a genuine compression tool. “It’s crafted⁣ in an extremely deceptive manner,” Raiu ‌notes. Additionally, the ⁣backdoor is “passive,” meaning it doesn’t actively ​reach⁢ out to a command-and-control server that‍ could potentially expose the operator’s identity. Instead, it patiently waits for the operator to establish a connection to the target machine⁢ via SSH and authenticate using a private key generated with the robust ED448 cryptographic‌ function.

    Potential Culprits: Non-US Groups with a History​ of Supply Chain Attacks

    While‌ the ​backdoor’s meticulous design could be attributed to US hackers, Raiu suggests ‌this is improbable, as the US typically refrains from sabotaging⁣ open-source ⁤projects. Moreover, if‍ the National Security Agency were involved, they would likely employ a quantum-resistant⁢ cryptographic function, which ED448 is ‍not. Raiu proposes that non-US ⁣groups with ‍a track record of supply chain attacks, such ‍as APT29 and ​ Cozy Bear, ⁢could be responsible. He⁣ highlights the SolarWinds attack as an example of a remarkably coordinated and effective software ‌supply chain attack that aligns more closely with the style of the XZ Utils backdoor compared‍ to the less​ sophisticated attacks carried out by APT41 or Lazarus.

    “It could very well be someone else,” says Aitel. “But I mean, if you’re looking for ⁤the most sophisticated supply ⁣chain ⁤attacks on ​the planet, that’s going to be our dear friends at the SVR.”

    The Future of Jia Tan and Open Source‍ Security

    Security researchers concur that Jia Tan‌ is unlikely to‍ be‍ a real individual or a lone ⁢actor. Instead, the persona appears to be⁣ the online manifestation⁤ of a novel tactic​ employed by a well-organized, government-backed group—a tactic that nearly succeeded. This implies that we should ‍anticipate ⁤the return of Jia ‌Tan under different‍ guises:⁤ seemingly polite and ‍enthusiastic ⁤contributors to open-source projects, concealing ​a government’s covert intentions within their code commits.

    Updated 4/3/2024​ at 12:30 pm ET​ to note the possibility of Israeli ⁣or Iranian involvement.

    Credibility Jia Tan Sabotage Scott XZ Utils
    Share. Facebook Twitter Copy Link
    Previous ArticleAmerican Women Traveling to Mexico for Abortions: 24-Hour Pill Access
    Next Article Opera Integrates Local LLM Downloads for Enhanced User Privacy

    Related Posts

    AI

    Get 1 Year of The Zero Byte for $30: Lawsuit Highlights Fake News

    October 21, 2024
    AI

    Get One Year of The Zero Byte for $5: How a Trump Win Could Unleash AI

    October 21, 2024
    AI

    Get One Year of The Zero Byte for $5: Sam Altman’s Eye-Scanning Orb Delivered

    October 17, 2024
    View 3 Comments

    3 Comments

    1. Saffron on March 24, 2024 6:00 pm

      “Jia Tan” – strikes me as the name you’d whisper around a campfire, spooking every techie in sight.

      Reply
    2. Aria Foster on April 18, 2024 5:16 pm

      ‘Jia Tan’ sounds like the villain in a cyber thriller, doesn’t he?

      Reply
    3. Robert J. Hawkins on April 30, 2024 9:45 am

      “Jia Tan” sounds like the kind of person you’d love to hate in an online game, right?

      Reply
    Leave A Reply Cancel Reply

    Top Posts

    Truecaller Unveils Web Client for Android: Seamless Caller ID and Spam Protection

    April 10, 2024

    M4 MacBook Pro Already in Development, According to Expert

    March 15, 2024

    Withings ScanWatch 2 and Light: Effortless Elegance for the Tech-Weary

    March 11, 2024
    Stay In Touch
    • Twitter
    • Instagram
    Latest Reviews

    Subscribe to Updates

    Get the latest tech news from The Zero Byte about tech.

    Please enable JavaScript in your browser to complete this form.
    Loading
    Most Popular

    Truecaller Unveils Web Client for Android: Seamless Caller ID and Spam Protection

    April 10, 2024

    M4 MacBook Pro Already in Development, According to Expert

    March 15, 2024

    Withings ScanWatch 2 and Light: Effortless Elegance for the Tech-Weary

    March 11, 2024
    Our Picks

    Get 1 Year of The Zero Byte for $30: Lawsuit Highlights Fake News

    October 21, 2024

    Get One Year of The Zero Byte for $5: How a Trump Win Could Unleash AI

    October 21, 2024

    Get One Year of The Zero Byte for $5: Sam Altman’s Eye-Scanning Orb Delivered

    October 17, 2024

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Please enable JavaScript in your browser to complete this form.
    Loading
    The Zero Byte
    Facebook X (Twitter) Instagram
    • Privacy Policy
    © 2025 The Zero Byte.

    Type above and press Enter to search. Press Esc to cancel.