Bonum Certa Men Certa

Linux Backdoors Revisited (New Revelations and Old Revelations)

Claude Elwood Shannon, the man who introduced entropy

Claude Elwood Shannon



Summary: An anonymous backdooring attempt against Linux goes a decade back, but a randomisation problem in today's Linux also seems possible (subverting encryption)

Jonathan Allen wrote this article about an incident mentioned also by Freedom to Tinker. Slashdot's summary goes like this, documenting news from one decade ago:



"Ed Felton writes about an incident, in 2003, in which someone tried to backdoor the Linux kernel. Back in 2003 Linux used BitKeeper to store the master copy of the Linux source code. If a developer wanted to propose a modification to the Linux code, they would submit their proposed change, and it would go through an organized approval process to decide whether the change would be accepted into the master code. But some people didn't like BitKeeper, so a second copy of the source code was kept in CVS. On November 5, 2003, Larry McAvoy noticed that there was a code change in the CVS copy that did not have a pointer to a record of approval. Investigation showed that the change had never been approved and, stranger yet, that this change did not appear in the primary BitKeeper repository at all. Further investigation determined that someone had apparently broken in electronically to the CVS server and inserted a small change to wait4: 'if ((options == (__WCLONE|__WALL)) && (current->uid = 0)) ...' A casual reading makes it look like innocuous error-checking code, but a careful reader would notice that, near the end of the first line, it said '= 0' rather than '== 0' so the effect of this code is to give root privileges to any piece of software that called wait4 in a particular way that is supposed to be invalid. In other words it's a classic backdoor. We don't know who it was that made the attempt—and we probably never will. But the attempt didn't work, because the Linux team was careful enough to notice that that this code was in the CVS repository without having gone through the normal approval process. 'Could this have been an NSA attack? Maybe. But there were many others who had the skill and motivation to carry out this attack,' writes Felton. 'Unless somebody confesses, or a smoking-gun document turns up, we'll never know.'"


Backdoors in Linux are a subject for jokes in Torvalds' mind, but given the above we should take this subject very seriously. In any system, for example, having no mechanism for randomness (like in some embedded devices) typically means that strong encryption (with high entropy) is not possible. Given new alleged "insecurities in the Linux /dev/random," as Bruce Schneier put it, Linux backdoors seem possible again. David Benfell said:

I'm guessing Schneier knows what the fuck he's talking about. If it is the same vulnerability, then Torvalds' defense is that the vulnerable source of entropy is only one of many. But if I read Schneier correctly, the result was still too predictable.


"On the other hand," says Benfell, "here's Theodore T'so from the comments:"

So I'm the maintainer for Linux's /dev/random driver. I've only had a chance to look at the paper very quickly, and I will at it more closely when I have more time, but what the authors of this paper seem to be worried about is not even close to the top of my list in terms of things I'm worried about.

First of all, the paper is incorrect in some minor details; the most significant error is its (untrue) claim that we stop gathering entropy when the entropy estimate for a given entropy pool is "full". Before July 2012, we went into a trickle mode where we only took in 1 in 096 values. Since then, the main way that we gather entropy, which is via add_interrupt_randomness(), has no such limit. This means that we will continue to collect entropy even if the input pool is apparently "full".

This is critical, because *secondly* their hypothetical attacks presume certain input distributions which have an incorrect entropy estimate ---| that is, either zero actual entropy but a high entropy estimate, or a high entropy, but a low entropy estimate. There has been no attempt by the paper's authors to determine whether the entropy gathered by Linux meets either of their hypothetical models, and in fact in the "Linux Pseudorandom Number Generator Revisited"[1], the analysis showed that our entropy estimator was actually pretty good, given the real-life inputs that we are able to obtain from an actual running Linux system.

[1]http://eprint.iacr.org/2012/251.pdf

The main thing which I am much more worried about is that on various embedded systems, which do not have a fine-grained clock, and which is reading from flash which has a much more deterministic timing for their operations, is that when userspace tries to generate long-term public keys immediately after the machine is taken out of the box and plugged in, that there isn't a sufficient amount of entropy, and since most userspace applications use /dev/urandom since they don't want to block, that they end up with keys that aren't very random. We had some really serious problems with this, which was written up in the "Mining Your Ps and Qs: Detection of Widespread Weak Keys in Network Devices" [2]paper, and the changes made in July 2012 were specifically designed to address these worries.

[2]https://www.factorable.net/paper.html

However, it may be that on certain systems, in particular ARM and MIPS based systems, where a long-term public key is generated very shortly after the first power-on, that there's enough randomness that the techniques used in [2]would not find any problems, but that might be not enough randomness to prevent our friends in Fort Meade from being able to brute force guess the possible public-private key pairs.

Speaking more generally, I'm a bit dubious about academic analysis which are primarily worried about recovering from the exposure of the state of the random pool. In practice, if the bad guy can grab the state of random pool, they probably have enough privileged access that they can do many more entertaining things, such as grabbing the user's passphrase or their long-term private key. Trying to preserve the amount of entropy in the pool, and making sure that we can extract as much uncertainty from the system as possible, are much higher priority things to worry about.

That's not to say that I might not make changes to /dev/random in reaction to academic analysis; I've made changes in reaction to [2], and I have changes queued for the next major kernel release up to make some changes to address concerns raised in [1]. However, protection against artificially constructed attacks is not the only thing which I am worried about. Things like making sure we have adequate entropy collection on all platforms, especially embedded ones, and adding some conservatism just in case SHA isn't a perfect random function are some of the other things which I am trying to balance as we make changes to /dev/random.


T'so, who is the former CTO of the Linux Foundation, at least acknowledges the possibility that there is a real issue here.

Recent Techrights' Posts

EPO General Consultative Committee (GCC) Agenda: Reduction of Staff's Salaries (Compared to Inflation)
knocking salaries down some more
What's 4Chan and Why It's So Problematic
Incels and losers converge around online echo chambers
Python is Attempting an Outreach to African-Americans, Microsoft Lunduke Has a Problem With That
Did he manage to brainwash himself into this ideology wherein bigotry is in fact tolerance, inclusion, equity?
IBM is Googlebombing Its Way Out of Trouble and Criticism
IBM is a dying giant
After Denial (of the Issues) Comes Censorship
Every critic of the status quo is "racist" and every criticism is "racism"
Intel, Facing Mass Layoffs (Including Many Key Engineers Who Work on Linux Kernel), is Pushing for Slop Inside Linux
replacing proper, well-tested code (and documentation thereof) with slop
More People Want to Quit Windows (Vista 10 is "End of Life"), Restricted Boot (UEFI) Makes That Harder
It's widely agreed (a consensus) that Restricted Boot is a bad thing for GNU/Linux
How We Managed to Make IRC Inclusive and Free Speech-Tolerant Without Banning People
People in IRC seldom agree on everything, more so if politics are aired and especially in the wrong context/s
Germany-Based Focus Online is Apparently Covering Up Cocaine Use at Europe's Second-Largest Institution, the European Patent Office
More contact details for the German press - Focus online
Photos From Richard Stallman's Talk in Argentina Earlier Today (Remote Talk)
Dr. Stallman's talk went ahead
 
Spanish Focus Coming Soon and Maturity of Site Search
We'll soon be focusing on Spain
Slopwatch: LLM Slopfarms Seem to be Slowing Down Somewhat
LLM addiction is a very unhealthy addiction
The "Nazi Bars"
We don't condone or condemn the label "Nazi Bar"
Thailand: Windows Down Sharply, Microsoft Loses Share to GNU/Linux
the Thai economy is strategic and relatively important in the region
Gaming Journalist and Guru Jason Schreier Says Microsoft is Indeed Behaving Like It Exits the Console Market
Remember that many shops no longer sell or stock XBox
Links 17/11/2025: ‘Agentic OS’ Backlash and Facebook ('Meta') Loses Yann Le Cun
Links for the day
Gemini Links 17/11/2025: Technology's Harm in Schools, 3D Printer Blurb
Links for the day
Coming Soon: EPO Trip in Spain
António Campinos being 'Marcosed'
Links 17/11/2025: "You Don't Need Animations" and Blocking Copyright-Infringing Sites Inevitably Goes Wrong
Links for the day
The Register MS: Slop is "FOMO" (Fear of Missing Out), FOMO is Funding Us
even former management (Editor in Chief of The Register MS) admitted to me it was aware of this issue
Difficult to Win Arguments When the Simple Facts Are Not on One's Side
Starting arguments over things when you know the facts (unlike money!) aren't on your side is a dumb move that can only ever result in severe loss of credibility
Tribalism Injures Projects
In Free software communities, there are many species and "breeds". Some developers are happy to work with everyone else based upon technical merit
No, There is Nothing Impressive About Slop Plagiarism-Enabled, Computer-Generated Images in Your Web Site...
When people use slop they do not broadcast an embrace of innovation; they merely signal they're lazy, unethical, and unscrupulous
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Sunday, November 16, 2025
IRC logs for Sunday, November 16, 2025
IRCNow Helped Techrights
If you want to gain more independence or "sovereignty" over your communications and need help setting things up (no prior experience setting up/configuring IRC), go to IRCNow
UEFI 'Restricted Boot' Will Usher in Rootkits Into Linux
Those of us who understand and value what it means to truly own our devices should definitely be alarmed by these trends
Plan for European Patent Office (EPO) Coverage This Month, Next Month, and Next Year
How much longer can European politicians ignore all this corruption?
opensource.net Dead Since Middle of Summer, opensource.org (OSI) Still Leaderless
At the moment the brand "Open Source" is misused so heavily that we have considered adding a new category to our Daily Links, focusing a lot less on "Open" and more on software freedom as a concept
Slopwatch: Google News Full of Slop
Google News has serious problems
Gemini Links 16/11/2025: The Cure for Slop, Rapsberry Pi Zero 2 W, and POSIX from Ada
Links for the day
NHS Data Breach Caused by Proprietary Software, as Usual, The Register MS Blames "Hackers" and "Cybercriminal Gang"
Nothing will get solved unless we have a rethink and media quits using the "hacker" narrative, which shifts blame from the holes to those who merely exploit them
IBM is Vanishing (First Moving, Then Going Away Completely)
Salary reduction is only the first step
Links 16/11/2025: Japan-China Tensions Grow, Surveillance Giant Google Checked for Breach of the Digital Markets Act (DMA)
Links for the day
Links 16/11/2025: Censorship Battles and Margaret Sullivan Speaks
Links for the day
German Media and German Politicians: Working for the Public or Manipulating the Public?
The "common person" does not have printing presses
Informing the Public of Suppressed Facts
We are all in this together
Canadian Linus Meets Finnish-American Linus
LTT does have a very large audience, which it can steer away from Microsoft and Windows
The UK's Online Safety Act (OSA) Discourages Technological Entities, Including Free Software Projects, Being Based in or Near the UK
When it comes to IRC hosting, we never had any serious speech restrictions imposed upon us by the UK
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Saturday, November 15, 2025
IRC logs for Saturday, November 15, 2025
Father of GNU Giving Keynote Talk Today, Father of Linux Collaborating With Linus Tech Tips (LTT)
Some time soon we can expect Linus Tech Tips (LTT) / Linus Media Group / Linus Gabriel Sebastian to produce something with Torvalds
Gemini Links 16/11/2025: Emacs Font Fun and UI x TUI x CLI
Links for the day
Flagging or Labelling LLM Slop Meaningfully to Discourage the Practice
We're still refining the annotation for better contrast
LLM Slop is an Addiction One Can Quit
Sites that crossed over to "the dark side" (slop) can still return, and even fully regain the trust lost by betraying people with 'botspew'.
BILD is Apparently Covering Up Cocaine Use at Europe's Second-Largest Institution, the European Patent Office, as It's Based on Germany
Journalist contact details
Techrights Site Search Pushed to 'Stable'
we've just added it to the navigation menu and footer
Situation Publishing's DevClass (Sister Site of The Register MS, Run by MS Tim) Has Been Abandoned, Microsoft's MS Tim Now Interjects Anti-Linux Directly Into The Register MS
Not only does this sell Microsoft; it's also googlebombing - as before - the real "maui" (or "MauiKit" in Linux).
Many IBM Workers to Become Unemployed a Few Weeks - Maybe Just Days - Before Christmas
as one last humiliating exercise IBM pimps/trots them out in social control media, telling "happy" stories
Slopwatch: LinuxSecurity, WebProNews, and Linux Journal (Slopfarms)
More fake articles about "Linux"
Links 15/11/2025: Openwashing of Kubernetes and Austerity Planned for Canada
Links for the day
Links 15/11/2025: "Small Web, Big Voice" and China Cracking Down on Slop
Links for the day
Links 15/11/2025: Science, Conflicts, and International Politics
Links for the day
Annus Horribilis at the European Patent Office (EPO)
The article explains how the EPO "Cocainegate" scandal is turning 2025 into an Annus Horribilis for Campinos
Links 15/11/2025: Latest in "Component Abuse Challenge" and Qt Keeps Promoting LLM Slop
Links for the day
Gemini Links 15/11/2025: Egoism, Misunderstood Universe, DeX, and "Why desktop Linux is growing"
Links for the day
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Friday, November 14, 2025
IRC logs for Friday, November 14, 2025
Richard Stallman Talk Tomorrow in Ethereum Cypherpunk Congress 2
It's not clear if a livestream of some kind will exist
Many "Last Days" at IBM on Allegedly the "Last Day" for IBM to RA People This Quarter
"Last day" is "social media code" for "got laid off", more so at IBM because they compel people to act like it's a happy departure with gratitude, photos and so on