Bonum Certa Men Certa

Edward Brocklesby (ejb) & Debian: Hacking expulsion cover-up in proximity to Oxford and GCHQ

posted by Roy Schestowitz on Jun 06, 2024,
updated Jun 24, 2024

Reprinted with permission from Daniel Pocock.

As written previously, I don't believe that Debian Developers can be expelled as such because the relationship between us is a relation of joint authorship.

Nonetheless, from time to time it is necessary to remove somebody's access to Debian infrastructure due to concerns about their integrity and other poor behavior. The first case of this was Shaya Potter, for WaReZ operations.

There is a pattern that has become very easy to see: if somebody is expelled in a very public manner then it is due to backstabbing by the corrupt leadership. The expulsion of Jacob Appelbaum based on falsified harassment claims was the most prominent example of backstabbing. On the other hand, when the leadership has failed to protect the security of the Debian distribution, the whole affair gets covered up. The expelled person is free to go elsewhere.

The most dramatic case that has been hidden from the public is that of Edward Brocklesby (ejb). Looking at Shaya Potter, we could follow his career path after his departure from Debian. Edward Brocklesby simply disappeared into obscurity. Did he even exist at all or was Edward Brocklesby a fake name for somebody who we don't really know?

The second notable point about the case of Edward Brocklesby is the list of packages he was maintaining. His package list was discussed after his exclusion:

Subject: Re: ejb's old packages--who want to adopt them?
Date: Tue, 25 Apr 2000 10:05:15 +0100
From: Steve McIntyre <stevem@chiark.greenend.org.uk>
To: Anthony Fok <foka@ualberta.ca>
CC: debian-private@lists.debian.org

On Tue, Apr 25, 2000 at 09:14:42AM +0100, Anthony Fok wrote: > >According to Joey's earlier post, here are the packages that ejb left >behind: > > archie, csh, eggdrop, gcc-m68k-gnu, hx, mh, mh-paper, mig-m68k-gnu, > pmake, sac, simh, simh-rsts-images, simh-unix-images, ssh2 > >Hope we can all pitch in and pick up one or two of them. Otherwise, >they'd have to be orphaned -> debian-qa, definitely before potato is >out, otherwise the bug reports would be unattended to.
I'll take pmake; we occasionally use it at work and it would be painful to lose it.
-- Steve McIntyre, Allstor Software smcintyr@allstor-sw.co.uk My PC page "Can't keep my eyes from the circling sky, "Tongue-tied & twisted, Just an earth-bound misfit, I..."

While discussing ejb's packages, nobody seemed to notice that these are just the packages that a serious bad guy would want to put backdoors into: shells, compilers and even the ssh2 package. There was incredible complacency about this.

In hindsight, it seems even more odd that the person maintaining those packages has simply vanished. In other words, the person maintaining those packages for a number of years may have been using a fake name.

This is the reality of security on Debian: the package maintainers may be fast at copying security patches from upstream and getting them released but they can't really understand what they are looking at. By excluding talented developers and dumbing down with groupthink, they reduce the amount of adult scrutiny on situations like this.

The failure of anybody to notice the risk of backdoors in those binaries is one of many glaring oversights in the EJB case.

Another thing people failed to notice is that Brocklesby was living in close proximity to the A40, that is the road from Oxford to the GCHQ office at Cheltenham. GCHQ doesn't publish a list of their employees in the free and open source software space, nonetheless, it is widely accepted that such people exist.

Edward J Brocklesby, Debian, Una P Brocklesby, Oxford

The IETF records show us he was interested in the development of standards for IRC.

His interest in standards or any other public activity seems to cease completely within a short time of the discovery of his activities around Debian.

The next big red flag in the way Debian handled the Edward Brocklesby affair is that they failed to immediately restrict his access to Debian infrastructure. For some weeks they engaged in a debate with him on the debian-private (widely leaked) secret cubby house. He almost fooled them to allow him to keep his access privileges.

The BBC obtained a secret tape recording of Kim Philby talking to Stasi agents.

In 1963, an MI6 colleague came to confront him with new evidence pointing to his work for the Soviets.

Philby bluffed and stalled.

...

Philby finishes with one piece of advice to the spies gathered before him that had served him well: never confess.

"If they confront you with a document with your own handwriting then it's a forgery - just deny everything…

"They interrogated me to break my nerve and force me to confess.

"And all I had to do really was keep my nerve. So my advice to you is to tell all your agents that they are never to confess."

Looking through debian-private, we can see Edward Brocklesby buying time. Philby was not the only one to use these tactics.

Ireland needs a high-level expert on cybersecurity in the European Parliament. Please see my nomination and promote it as widely as possible as we count down to the vote this Friday, 7 June.

GCHQ, Chelthenham

More news and policy statements regarding my campaign for European Parliament:

Please print my brochure if you want Ireland to change

Other Recent Techrights' Posts

"I Hated Working at IBM. They Were the Most Unfriendly People."
Don't forget what Watson the son did to a poor woman on a plane
Staff Union of the EPO (SUEPO) is Taking the New Pension Scheme (NPS) to an International Tribunal (ILOAT)
SUEPO wants more EPO staff to participate in collective action
Stella Assange and the Legal Team Speak to the Media a Day After WikiLeaks Founder Julian Assange Arrives in Australia
Published yesterday by a number of mainstream publishers
Over at Tux Machines...
GNU/Linux news for the past day
[Video] The 'Dangerous Precedent' (Jen Robinson on Assange Plea Bargain)
Published 3 hours ago in Australia
Microsoft is Losing Its Grip on Bulgaria
now may be a good time to look into statistics from Bulgaria
LinuxSecurity.com Back to Relaying Anti-Linux FUD From Microsoft, Using Microsoft Chatbots That Recycle and Add Permutations to the FUD
They're killing the Web every time they do this
 
Links 28/06/2024: More Attacks on the Press, More Censorship in Russia
Links for the day
Gemini Links 28/06/2024: Christmas Prematurely, Self-hosting
Links for the day
IBM: So Long, Suckers. Your Free OS is Now Proprietary. Pay IBM or Else.
almost exactly a year after turning RHEL into proprietary software
Vista 11 is Doomed and Despite Lack of Adoption Microsoft Already Speaks of Vapourware ("12")
"Microsoft has pulled a Windows 11 update after users reported boot loops and startup failures."
ChromeOS Reaches Highest Share in Years at the World's Most Populous Nation, Windows Now at All-Time Low of 13%
We're talking about India today
[Video] "It Is Incredible That Julian Assange Survives"
There was a positive and mutual relationship between Wikileaks and Dr Jill Stein
Never Assume That Because the Law Exists the Powerful Will Follow the Law
Who's going to hold them accountable now?
Nearly a Month Has Passed and Nobody at the Debian Project Even Attempted to Explain What Seems Like Back-dooring of Debian (and Hundreds of Distros That Are Debian-Derived)
I can cynically guess that only matters when a user with a Chinese name does it
[Video] Julian Assange Explains Wikileaks' Logistics
predating indefinite detention
IBM Was Never the "Good Guy", Just a Self-Serving and Opportunistic Money- and Power-Hungry Monopolist, Living Off of Taxpayers' Money (Government Contracts)
The Nazi Party of Germany was its second-biggest client at one point and now it's looking to profit from the work of slaves
State of the News (and Depletion of Journalism Online, Not Just Offline)
Newspapers are not coming back and the Web is not coming back either
GNU/Linux Consolidates in North America
Android rising a lot this year, too
[Meme] More Monopolies Granted While Patent Examiners Die (Overworking for Less Compensation)
Work more; Get less
IRC Proceedings: Thursday, June 27, 2024
IRC logs for Thursday, June 27, 2024
RIP Daniel Bristot de Oliveira, Red Hat death
Reprinted with permission from Daniel Pocock
European Commission fooled by IBM Red Hat merger risk to source code
Reprinted with permission from Daniel Pocock
Links 27/06/2024: Black-Lives-Matter-Poster-Related Lawsuit, Misinformation and Propaganda by Chinese Userfarms
Links for the day
Gemini Links 27/06/2024: Rogue Legends and Old Computers
Links for the day
[Meme] They Think of Their Business Partner, Microsoft
Think.
At the Cusp of Productivity
Work in progress: a critique of terms of service (ToS) in "modern" computing
The Free Software Foundation (FSF) is Becoming More European Than the Google- and Microsoft-Funded 'FSFE' (Fake 'FSF', a Case of Identity Theft)
The Board of Directors of the FSF is now all European as far as women (3) go
[Meme] Meanwhile at IBM's Headquarters
Old white men can find common themes to laugh at in IBM
IBM's Board is a Men's Club, Unlike the FSF's, But Red Hat/IBM Are Trolling the Community Using the "Diversity Shtick"
CoC-fighting over diversity to distract from their own failings
John Gilmore, Cofounder of the Electronic Frontier Foundation, Joins the FSF's Board
it's already riling up the Microsofters and misogynists
Links 27/06/2024: Microsoft's Chief Brand Offices Kathleen Hall to Leave, The Beauty of Blogging, Ukraine Updates
Links for the day
Microsoft Got Lost in Bermuda
based on far too little data
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Wednesday, June 26, 2024
IRC logs for Wednesday, June 26, 2024
Microsofter Throwing Stones in a Glasshouse Again
"Life is imitating art" and if you're a BS artist, your life must be BS
Far Too Young to Die
He seemed to be healthy
Virgin Islands, Marshall Islands, Guam and Other American Satellites Drift Further Away From Microsoft
So even US-controlled islands are moving away from Windows, little by little...
Let's Encrypt is Dying in Geminispace (Now Down Very Sharply to 6%), More People Self-Sign as They Certainly Should
Abandoning a fake security model?
No More Justice for Assange?
Not the site anyway
[Meme] "No News is Good News"
2 days have passed and still not a word
Northern Mariana Islands May Have Been Taken Over by Debian!!
The place is strategic for military reasons (like a giant aircraft carrier with running water)
Birthday With His Family
Julian Assange was born 3 July 1971
Julian Assange on Cryptographically-deniable Block Storage Device (aka Marutukku)
An oldie
Links 26/06/2024: US State Department Controlling YouTube, Artificial Intelligence (AI) Hype on the Brink as "Losses Balloon"
Links for the day
GNU/Linux Back Above 4% (in statCounter)
happened minutes or a few hours ago
Free Assange! (by Alexandre Oliva)
Reprinted with permission from Alexandre Oliva
Julian Assange & Debian: was he a developer?
Reprinted with permission from Daniel Pocock
Links 26/06/2024: More on Hey Hi (AI) Bubble Fading, RIAA Steps in
Links for the day
Gemini Links 26/06/2024: UAF Botanical Garden and YouTube Workarounds
Links for the day
Microsoft Market Share Falling to New Lows in Aruba
Being below 20% in America is the exception, not the norm
Streaming in a Few Minutes: Julian Assange Press Conference
They test the microphone now.
[Video] Julian Assange Arrives Safely in Australia
even the person on the air cried
Debian Project Still Has a Lot of Explaining to Do...
Assange was actually a Debian Developer
[Meme] When Ian (of Debian) Was Still Alive
I wasn't always a Debian Developer...
"Julian Assange is Free"
Published ~34 minutes ago
GNU/Linux Userbase Surging in Iceland
Maybe there's something big going on, like people deleting Vista 11 in droves and installing GNU/Linux instead
Jennifer Robinson: "After 14 years of legal battles, Julian Assange can go home a free man”
She explains the implications for the general freedom of the press
Judge: Assange Leaves Court 'A Free Man'
on his way to Australia now
Julian Assange verdict: guilty, not guilty or blackmailed
Reprinted with permission from Daniel Pocock
12 Months Ago the FSF Said It Would Issue a Statement on IBM Taking RHEL Proprietary
Statement never happened
Sheriff of Cork & Debian Edward Brocklesby or Brockelsby Street confusion
Reprinted with permission from Daniel Pocock
Microsoft's Bing Fall From 2.6% Before LLM Hype to Just 0.79% Right Now in Russia
statCounter's data
[Meme] Speaking Truth to Power (Still Easier in the West Than in Russia/BRIC)
Different people, different outcomes
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Tuesday, June 25, 2024
IRC logs for Tuesday, June 25, 2024
The Plot to Silence (or Deplatform) Techrights
This past month I've been spending time working on the text of an online publication
[Meme] Julian Assange's Lawyers Need to Ensure Assange Maintains Freedom to Publish
Let's ensure he can continue to publish
"Conviction for a Crime he Did Not Commit," Said Jennifer Robinson
Robinson is the kind of woman accomplisher we should look up to
Trying to Make Blogs (Independent and Mostly Decentralised Platforms) What Comes After Social Control Media
Social Control Networks 'stole the thunder' of blogs, but can we get back to blogs?
Julian Assange Has Landed
There will probably be some press interviews some time this month or next month