Bonum Certa Men Certa

Linux Backdoors Revisited (New Revelations and Old Revelations)

Claude Elwood Shannon, the man who introduced entropy

Claude Elwood Shannon



Summary: An anonymous backdooring attempt against Linux goes a decade back, but a randomisation problem in today's Linux also seems possible (subverting encryption)

Jonathan Allen wrote this article about an incident mentioned also by Freedom to Tinker. Slashdot's summary goes like this, documenting news from one decade ago:



"Ed Felton writes about an incident, in 2003, in which someone tried to backdoor the Linux kernel. Back in 2003 Linux used BitKeeper to store the master copy of the Linux source code. If a developer wanted to propose a modification to the Linux code, they would submit their proposed change, and it would go through an organized approval process to decide whether the change would be accepted into the master code. But some people didn't like BitKeeper, so a second copy of the source code was kept in CVS. On November 5, 2003, Larry McAvoy noticed that there was a code change in the CVS copy that did not have a pointer to a record of approval. Investigation showed that the change had never been approved and, stranger yet, that this change did not appear in the primary BitKeeper repository at all. Further investigation determined that someone had apparently broken in electronically to the CVS server and inserted a small change to wait4: 'if ((options == (__WCLONE|__WALL)) && (current->uid = 0)) ...' A casual reading makes it look like innocuous error-checking code, but a careful reader would notice that, near the end of the first line, it said '= 0' rather than '== 0' so the effect of this code is to give root privileges to any piece of software that called wait4 in a particular way that is supposed to be invalid. In other words it's a classic backdoor. We don't know who it was that made the attempt—and we probably never will. But the attempt didn't work, because the Linux team was careful enough to notice that that this code was in the CVS repository without having gone through the normal approval process. 'Could this have been an NSA attack? Maybe. But there were many others who had the skill and motivation to carry out this attack,' writes Felton. 'Unless somebody confesses, or a smoking-gun document turns up, we'll never know.'"


Backdoors in Linux are a subject for jokes in Torvalds' mind, but given the above we should take this subject very seriously. In any system, for example, having no mechanism for randomness (like in some embedded devices) typically means that strong encryption (with high entropy) is not possible. Given new alleged "insecurities in the Linux /dev/random," as Bruce Schneier put it, Linux backdoors seem possible again. David Benfell said:

I'm guessing Schneier knows what the fuck he's talking about. If it is the same vulnerability, then Torvalds' defense is that the vulnerable source of entropy is only one of many. But if I read Schneier correctly, the result was still too predictable.


"On the other hand," says Benfell, "here's Theodore T'so from the comments:"

So I'm the maintainer for Linux's /dev/random driver. I've only had a chance to look at the paper very quickly, and I will at it more closely when I have more time, but what the authors of this paper seem to be worried about is not even close to the top of my list in terms of things I'm worried about.

First of all, the paper is incorrect in some minor details; the most significant error is its (untrue) claim that we stop gathering entropy when the entropy estimate for a given entropy pool is "full". Before July 2012, we went into a trickle mode where we only took in 1 in 096 values. Since then, the main way that we gather entropy, which is via add_interrupt_randomness(), has no such limit. This means that we will continue to collect entropy even if the input pool is apparently "full".

This is critical, because *secondly* their hypothetical attacks presume certain input distributions which have an incorrect entropy estimate ---| that is, either zero actual entropy but a high entropy estimate, or a high entropy, but a low entropy estimate. There has been no attempt by the paper's authors to determine whether the entropy gathered by Linux meets either of their hypothetical models, and in fact in the "Linux Pseudorandom Number Generator Revisited"[1], the analysis showed that our entropy estimator was actually pretty good, given the real-life inputs that we are able to obtain from an actual running Linux system.

[1]http://eprint.iacr.org/2012/251.pdf

The main thing which I am much more worried about is that on various embedded systems, which do not have a fine-grained clock, and which is reading from flash which has a much more deterministic timing for their operations, is that when userspace tries to generate long-term public keys immediately after the machine is taken out of the box and plugged in, that there isn't a sufficient amount of entropy, and since most userspace applications use /dev/urandom since they don't want to block, that they end up with keys that aren't very random. We had some really serious problems with this, which was written up in the "Mining Your Ps and Qs: Detection of Widespread Weak Keys in Network Devices" [2]paper, and the changes made in July 2012 were specifically designed to address these worries.

[2]https://www.factorable.net/paper.html

However, it may be that on certain systems, in particular ARM and MIPS based systems, where a long-term public key is generated very shortly after the first power-on, that there's enough randomness that the techniques used in [2]would not find any problems, but that might be not enough randomness to prevent our friends in Fort Meade from being able to brute force guess the possible public-private key pairs.

Speaking more generally, I'm a bit dubious about academic analysis which are primarily worried about recovering from the exposure of the state of the random pool. In practice, if the bad guy can grab the state of random pool, they probably have enough privileged access that they can do many more entertaining things, such as grabbing the user's passphrase or their long-term private key. Trying to preserve the amount of entropy in the pool, and making sure that we can extract as much uncertainty from the system as possible, are much higher priority things to worry about.

That's not to say that I might not make changes to /dev/random in reaction to academic analysis; I've made changes in reaction to [2], and I have changes queued for the next major kernel release up to make some changes to address concerns raised in [1]. However, protection against artificially constructed attacks is not the only thing which I am worried about. Things like making sure we have adequate entropy collection on all platforms, especially embedded ones, and adding some conservatism just in case SHA isn't a perfect random function are some of the other things which I am trying to balance as we make changes to /dev/random.


T'so, who is the former CTO of the Linux Foundation, at least acknowledges the possibility that there is a real issue here.

Recent Techrights' Posts

SLAPP Censorship - Part 168 Out of 200: When Choosing Clients Recklessly and Poorly Self-Harm is Inevitable
"If you're doing something hard and nobody hates it, you probably aren't doing it. If the right people hate it and those people happen to be some of the worst people alive, so much the better."
 
FSF Staff Uses 'CoC' to Stop Conversation About Autistici/Inventati in Relation to Free Software
The list is already heavily moderated
IBM Allegedly Stopped Hiring (This Tends to Coincide With Mass Layoffs)
Is a hiring freeze an echo of layoffs? Yes, definitely.
Something Big is Happening at IBM This Week/Month
Some people at IBM (and Red Hat) are panicking
Gemini Links 01/09/2026: Biscuits, Epstein Files, Power Users, and Alhena 5.6.8
Links for the day
Links 01/09/2026: Almost 5,000 Missing/Dead in Nepal-China Flood and Marijuana Factory Explodes
Links for the day
September at IBM: Silent Layoffs on Day 1
PIPocalypse at IBM
Last Month IRC Entered Its 39th Year and It's Still Growing (New IRC Networks)
There are 511+ known IRC networks
Links 01/09/2026: Climate, Disinformation, Microsoft Overworking People
Links for the day
Richard Stallman's Site Still Offline (Third Day), But Richard Stallman is Active Online
he is busy online despite his site not being accessible so far this week
PIP Layoffs at Microsoft, Even in India
Microsoft is trying to hide the true scale of the layoffs
Layoff Trackers Are a Sham, They're Like US 'Unemployment Data'
Layoff trackers are similarly misleading as they only measure what companies openly admit and register with WARN notices
The Peculiar Case of OSNews, Which Experiments With Slopfarming
It wasn't published in error. It has been there for two months.
Russian Federation is Removing Windows From Computers
Windows is going "out of fashion"
XBox CEO Has No Clue What She is Selling
Some people believe Microsoft will parcel and offload the whole "gaming" unit to some other companies
analognowhere.com and xkcd.com Selling Physical Copies of Webcomics
That's one way to support their work
PIP/GVSA at Microsoft: Mass Layoffs Disguised as Something Else
Microsoft is trying to cheapen the workforce because the numbers don't add up
Microsoft Lunduke Uses Twitter ("X") Because It's Algorithmically Designed to Boost His Worldview/s, He Ignores What "X" Is
Maybe all those people really deserve one another
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Monday, August 31, 2026
IRC logs for Monday, August 31, 2026
Censorship by Threats
It should be noted that the Web site of Richard Stallman will soon enter its third day of downtime
In Romania, GNU/Linux Reaches 6%, According to Clownflare
Tomorrow we'll see the latest data from statCounter (for September)
Gemini Links 01/09/2026: Denali Park Train Trip, Crafts, and Community-Building in smol.pub
Links for the day
Microsoft Workers Doing 80 Hours a Week After Microsoft Culled Their Colleagues
there are days when they work 17 hours a day (barely any time left to sleep and eat) and work starts at 5AM
IBM Defrauds Shareholders With Fake News (Bribed Press) About "Quantum"
That says a lot about the state of "Tech Giants" and also the utterly shameless state of the media
Record Highs for GNU/Linux, Especially in the United States of America
the "market share" of GNU/Linux is about 9%, still about a third of what Vista 11 stands at
PIPocalypse at IBM
Silent layoffs
Spending Over a Million Bucks on Lawsuits Abroad When There's a Big Mortgage to Pay in America
Priorities, priorities...
Gemini Links 31/08/2026: Announcing ROOPHLOCH 2026, smol.pub Discussion, and LLM Plagiarism Engines Target Geminispace
Links for the day
Richard Stallman's GNU Turns 43 in 4 Weeks, FSF Growing
In a few weeks GNU turns 43
IBM's Cuts Are Worsening Security in GNU/Linux
IBM is still run by the same idiot who proposed taking over Red Hat
Microsoft: Work Weekends Too
Microsoft literally working its workers to death
Links 31/08/2026: Anthropic Sued Again for Copyright Infringement of Massive Scale, 'Tokenmaxxing' Shows Slop is a Worthless Liability
Links for the day
Links 31/08/2026: "Teslas Are Still Driving Into Oncoming Freight Trains" and "LLM Moats Quickly Evaporating"
Links for the day
Stallman Has Explained Slop is "Marketing Hype Campaign" and Torvalds Agreed. The Difference is the Bribes.
So be like Stallman
Debian Project Discards About 25% of the Votes on LLM Slop, Microsoft Votes in the General Resolution (GR)
"[t]he rules of the vote saw community members asked to rank each of the eight proposals. Just under 600 people voted, but Debian’s election team rejected many for unspecified reasons, leaving almost 450 valid votes to count."
Essentiality of Rest and Killing Oneself for Vicious Companies
Working for Microsoft is foolish
In the UK, Bing (Microsoft) Down to Lowest Level Since January
our tax money being passed to Microsoft via MoUs (back door deals with kickbacks)
SLAPP Censorship - Part 167 Out of 200: The Court of Appeal Might be the Next Step
Today is our last vacation day
German Government Sponsors IBM Because of GNU/Linux
Flatpak is sponsored by, run, and controlled by IBM
Richard Stallman Speaks to Christine Hall of FOSS Force, stallman.org is Down for Over a Day
interview does a good job addressing the hype about LLMs too
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Sunday, August 30, 2026
IRC logs for Sunday, August 30, 2026
Gemini Links 31/08/2026: Holidays, Stream of Consciousness, and Posting Online
Links for the day
Anniversaries Next Month
The month should be otherwise quiet and uneventful for us
Coding is Not Obsolete
we drown ourselves in chaff to meet "LOC" objectives while ignoring everything else
Microsoft Layoffs Perpetual But Silent, People Pushed Out Using Pressure or Incentive Schemes
Earlier this month we named some of the programs
Links 30/08/2026: Apple Rant and LLM (Slop) Scrapers Target Gemini Protocol and Gopher
Links for the day
Salaries Are Counted in Money, Not in Participation in the Employer's Scheme
articles greatly exaggerating GAFAM salaries
Walls in Free Software
mind your own business and move on
Even Linux Cannot Cope With Slop
Bots on the Web are truly obnoxious
What a Summer!
Tomorrow is the last day of this month
Links 30/08/2026: Soldiers in Niger Attack Presidential Palace and Airport, Nepali City Struggles to Handle the Many Dead Bodies
Links for the day
Clownflare Sees GNU/Linux Rising to 11% This Past Week
Is it the year of "Linux in China"?
Links 30/08/2026: Russian Strike on a Ukrainian Warehouse and Rhetoric Escalations
Links for the day
Gemini Links 30/08/2026: Photography, Paper Books, Linux Kernel and the Debian Projects Permitting Slop Plagiarism
Links for the day
Imagine a World Where Nobody Fights for Software (and Computing) Freedom
The community keeps fighting back, so some of these ambitions are delayed or watered down
FSF Has Grown (More Staff) After a Year of Financial Growth
On October 4 the FSF turns 41
GNU/Linux Has Become More Mainstream in the United Kingdom
It's a long weekend here and we guess some people dabble in GNU/Linux migrations, at least at home
SLAPP Censorship - Part 166 Out of 200: Garrett Wasn't Found Innocent Per Se, the Court Wanted More Evidence of Who Was Behind Particular Accounts Using Tor
It's complicated
Criminals Don't Obey Laws, California Does Not Enhance Online Safety
It has been a while since we last mentioned so-called 'age-verification' laws
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Saturday, August 29, 2026
IRC logs for Saturday, August 29, 2026