Bonum Certa Men Certa

Edward Brockelsby: how expelled hacker took over Debian's SSH2 package

posted by Roy Schestowitz on Jun 08, 2024

Reprinted with permission from Daniel Pocock.

Here is the list of changelog entries for the ssh2 package.

Here is the first upload from Edward Brocklesby after he takes over the package. Chilling.

Format: 1.6
Date: Fri, 26 Nov 1999 20:29:30 +0000
Source: ssh2
Binary: ssh2
Architecture: source i386
Version: 2.0.13-4
Distribution: unstable
Urgency: low
Maintainer: Edward Brocklesby <ejb@debian.org>
Description: 
 ssh2       - a secure replacement for rlogin, rsh, and rcp
Closes: 38705 39993 41100 46708 47030 47364
Changes: 
 ssh2 (2.0.13-4) unstable; urgency=low
 .
   * New Maintainer.
   * Suggest ssh-nonfree, not ssh.
   * Change 2222 to 22 in README.Debian (closes: #46708).
   * Don't link ssh against xlib6g.
   * Don't use ssh's own zlib, link with libz1 (closes: #39993).
   * Fix type in /etc/init.d/ssh2 (closes: #41100).
   * Change default $PATH to /bin:/usr/bin (closes: #47364).
   * Add a note about using ssh-keygen2 -r to the manpage (closes: #47030).
   * Suggests ssh-socks as well as ssh.
   * Prints a connection closed message when you log off (closes: #38705).

This was a long time before the Reproducible Builds project started. We have no idea if the binaries uploaded by Brocklesby correspond to the source code. At the time, people were simply trusted to compile the binaries on their home PC and upload them to the archive for everybody else to use. Scary, but true.

More scary, when they realized he was up to something they made no investigation into these binaries whatsoever. Looking at their discussions in hindsight, it didn't even occur to them, Debian people are so mediocre about security. They are obsessed with looking down their noses at people but don't understand what they see in front of them.

It looks like he was simply watching for other maintainers to lose interest and then he would take over their packages. Not every package though, only the packages that were really security critical like SSH, compilers and shells.

The rogue elements of Debian spent over $120,000 to attack me with lawyers after my father died. They made no credible inquiry into the activities of real hackers. They only care about making political attacks on volunteers. Security is above their pay grade.

It is now more than 48 hours after my first disclosure about the Edward Brocklesby affair and there is no comment whatsoever from the Debian security team. The only comments they make are to attack me personally, a reprisal for raising another serious security concern.

Read more articles about the mysterious Edward Brocklesby & Debian affair.

Other Recent Techrights' Posts

Books About Bubbles
calling things "AI" and "AIs" can mislead the reader
Links 08/12/2025: Slop Failing and Windows Users Won't 'Upgrade' Due to Slop
Links for the day
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Sunday, December 07, 2025
IRC logs for Sunday, December 07, 2025
IBM's Mass Layoffs Will Continue Until Morale Improves
From recent hours
Links 07/12/2025: Political Catchup, Conflicts, Environmentalism
Links for the day
Gemini Links 07/12/2025: "Lazy Saturday" and Kubernetes With FreeBSD
Links for the day
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Saturday, December 06, 2025
IRC logs for Saturday, December 06, 2025
Links 06/12/2025: Science, Hardware, and Slop Fatigue
Links for the day
Contact Your National Representatives (Delegates) at the EPO, Here Are All the E-mail Addresses
We'll say more about this next week
Hopefully Slopwatch is Dying
Some of the offending sites we used to keep abreast of descended into a lull
Links 06/12/2025: Panic in the Slop (Chatbots) Industry and Perplexity Sued by New York Times for Plagiarising Articles Under Guise of "AI"
Links for the day
European Patent Office Issues: Points to Raise or Factoids to Share With Delegates of the EPO's Administrative Council
use their native language/tongue
European Readers, Get Ready to Contact Your National Representatives (Delegates) in the EPO's Administrative Council
Perfect timing might be Sunday or Monday
Why We'll Continue Our IBM/Red Hat Focus in 2026
There will be many more departures not only later this month but also next month
Links 06/12/2025: Slop's "Jeopardy Phenomenon" and RAM Shortage
Links for the day
Gemini Links 06/12/2025: Memories, "Sweetness and Burn", and Hope
Links for the day
Every Site That Uses Clownflare Had Worse Downtime/Uptime Record Than Ours
And the same goes for Azure and AWS
Software Freedom Conservancy (SFC) Does Not Work for Freedom, It Works to Secure the Massive Salary of Its President And Executive Director
We must be very effective then
Why (and When) I Become an 'Activist' Against Corruption and Abuse
The dictatorship bans criticism of the dictatorship. That's when there's a deadlock.
EPO Call for Action: Get Ready to Contact Your National Delegates, We Need to Remind Them That They Represent People
Today or tomorrow we'll publish contact details for national representatives in nearly 50 European nations
Links 05/12/2025: More Restrictions on Social Control Media and Slop, "Hype Can Turn to Backlash"
Links for the day
Like With Red Hat and Other IBM Acquisitions, the RAs (Layoffs) Seem to Already Extend to HashiCorp
Of course it is possible that HashiCorp staff just got PIP'ed or saw the writings on the wall and left [...] IBM is just a dying giant
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Friday, December 05, 2025
IRC logs for Friday, December 05, 2025