Bonum Certa Men Certa

Edward Brocklesby (ejb) & Debian: Hacking expulsion cover-up in proximity to Oxford and GCHQ

posted by Roy Schestowitz on Jun 06, 2024,
updated Jun 24, 2024

Reprinted with permission from Daniel Pocock.

As written previously, I don't believe that Debian Developers can be expelled as such because the relationship between us is a relation of joint authorship.

Nonetheless, from time to time it is necessary to remove somebody's access to Debian infrastructure due to concerns about their integrity and other poor behavior. The first case of this was Shaya Potter, for WaReZ operations.

There is a pattern that has become very easy to see: if somebody is expelled in a very public manner then it is due to backstabbing by the corrupt leadership. The expulsion of Jacob Appelbaum based on falsified harassment claims was the most prominent example of backstabbing. On the other hand, when the leadership has failed to protect the security of the Debian distribution, the whole affair gets covered up. The expelled person is free to go elsewhere.

The most dramatic case that has been hidden from the public is that of Edward Brocklesby (ejb). Looking at Shaya Potter, we could follow his career path after his departure from Debian. Edward Brocklesby simply disappeared into obscurity. Did he even exist at all or was Edward Brocklesby a fake name for somebody who we don't really know?

The second notable point about the case of Edward Brocklesby is the list of packages he was maintaining. His package list was discussed after his exclusion:

Subject: Re: ejb's old packages--who want to adopt them?
Date: Tue, 25 Apr 2000 10:05:15 +0100
From: Steve McIntyre <stevem@chiark.greenend.org.uk>
To: Anthony Fok <foka@ualberta.ca>
CC: debian-private@lists.debian.org

On Tue, Apr 25, 2000 at 09:14:42AM +0100, Anthony Fok wrote: > >According to Joey's earlier post, here are the packages that ejb left >behind: > > archie, csh, eggdrop, gcc-m68k-gnu, hx, mh, mh-paper, mig-m68k-gnu, > pmake, sac, simh, simh-rsts-images, simh-unix-images, ssh2 > >Hope we can all pitch in and pick up one or two of them. Otherwise, >they'd have to be orphaned -> debian-qa, definitely before potato is >out, otherwise the bug reports would be unattended to.
I'll take pmake; we occasionally use it at work and it would be painful to lose it.
-- Steve McIntyre, Allstor Software smcintyr@allstor-sw.co.uk My PC page "Can't keep my eyes from the circling sky, "Tongue-tied & twisted, Just an earth-bound misfit, I..."

While discussing ejb's packages, nobody seemed to notice that these are just the packages that a serious bad guy would want to put backdoors into: shells, compilers and even the ssh2 package. There was incredible complacency about this.

In hindsight, it seems even more odd that the person maintaining those packages has simply vanished. In other words, the person maintaining those packages for a number of years may have been using a fake name.

This is the reality of security on Debian: the package maintainers may be fast at copying security patches from upstream and getting them released but they can't really understand what they are looking at. By excluding talented developers and dumbing down with groupthink, they reduce the amount of adult scrutiny on situations like this.

The failure of anybody to notice the risk of backdoors in those binaries is one of many glaring oversights in the EJB case.

Another thing people failed to notice is that Brocklesby was living in close proximity to the A40, that is the road from Oxford to the GCHQ office at Cheltenham. GCHQ doesn't publish a list of their employees in the free and open source software space, nonetheless, it is widely accepted that such people exist.

Edward J Brocklesby, Debian, Una P Brocklesby, Oxford

The IETF records show us he was interested in the development of standards for IRC.

His interest in standards or any other public activity seems to cease completely within a short time of the discovery of his activities around Debian.

The next big red flag in the way Debian handled the Edward Brocklesby affair is that they failed to immediately restrict his access to Debian infrastructure. For some weeks they engaged in a debate with him on the debian-private (widely leaked) secret cubby house. He almost fooled them to allow him to keep his access privileges.

The BBC obtained a secret tape recording of Kim Philby talking to Stasi agents.

In 1963, an MI6 colleague came to confront him with new evidence pointing to his work for the Soviets.

Philby bluffed and stalled.

...

Philby finishes with one piece of advice to the spies gathered before him that had served him well: never confess.

"If they confront you with a document with your own handwriting then it's a forgery - just deny everything…

"They interrogated me to break my nerve and force me to confess.

"And all I had to do really was keep my nerve. So my advice to you is to tell all your agents that they are never to confess."

Looking through debian-private, we can see Edward Brocklesby buying time. Philby was not the only one to use these tactics.

Ireland needs a high-level expert on cybersecurity in the European Parliament. Please see my nomination and promote it as widely as possible as we count down to the vote this Friday, 7 June.

GCHQ, Chelthenham

More news and policy statements regarding my campaign for European Parliament:

Please print my brochure if you want Ireland to change

Other Recent Techrights' Posts

"How Many Friends Do You Have?"
"Do bots count?" "Friends in Facebook?" "Does a girlfriend chatbot count as a friend?"
Solicitors Regulation Authority (SRA) Responds to Crises Only After It's Way Too Late
The SRA does not do its job. The new chief's job is face-saving PR in the media.
The Techrights Team Makes the Platform Faster
The infrastructure is already fast
France Does Not Need Digital Weapons Disguised as Social and as Media
French people lost interest in Social Control 'Media' (or Networks)
EPO "Productivity" Will Fall Off a Cliff If Examiners Stick to the European Patent Convention (EPC) and Follow the Real Rules
The EPO's "Cocaine Communication Manager" would hate to see the next "productivity" metrics
The Problem is Not Technology, the Problem is Really Bad Things Sold or Imposed as "Tech" (Like a Religion Built Around Technology)
Don't hate technology, hate the corporations that abuse it to promote coercion, exploitation etc.
Resisting IBM and EPO Corruption
Rise up against EPO dictatorship next week
Where Slop Meets Ghostwriting: It's a False Analogy
It's a false analogy
 
Links 18/02/2026: Gig 'Economy' Condemned, Microsoft Insulting/Stressing People With False Slop Predictions
Links for the day
Twitter Falling to 1% in Africa's Largest Nation (Algeria)
About 15 years ago the regime in Egypt got toppled (and others had been too) partly because of social control media such as Twitter
Mozilla Firefox Died in Afghanistan
Mozilla has been a complete disaster
Gemini Links 18/02/2026: Astronomy and Texinfo
Links for the day
Are IBM CEO and IBM CFO Ready for Financial Audit That Topples the Shares by 50% in One Day?
The same "chefs" that cooked up Kyndryl Holdings Inc are still in charge of the IBM kitchen
"Senior AI Reporter" at Slop Technica/Ars Sloppica Has Written Nothing in Nearly a Week, Did Conde Nast Suspend Him for Fake Articles With Fake Quotes?
Slop Technica/Ars Sloppica is having a serious credibility issue right now
Linux Foundation Puts Slop Images, Not Just Slop Text, in Linux.com
More of the same then
The Register MS Paid-for 'Articles' (Ads) Seem to be LLM Slop Again
If it's true that The Register MS is resorting to these marketing tactics, will they later delete the evidence (as they did months ago)?
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Tuesday, February 17, 2026
IRC logs for Tuesday, February 17, 2026
Microsoft Had Mass Layoffs Every Month Last Year, This Year It's Delaying a Lot to "Prove" Rumours That Crashed Its Stock... 'Wrong'
Building a bigger snowball for later
Red Hat Is Not a Company Anymore, Amid Bluewashing and Mass Layoffs It's Merely IBM "Division" or "Brand" or "Product"
systemd at this point is sort of like IBM/Microsoft thing
IBM suffers "worst weekly drop in six years", Microsoft's MSN calls it "buying opportunity"
Ask Cramer what to do
Still Some Slopfarms in View, Sometimes Targetting "Linux"
That's a total of at least 4 in Google News today, coming from 3 sources
Gemini Links 17/02/2026: 3D-Printed Stainless Steel Smartwatch and Gopher Bay Offline
Links for the day
Links 17/02/2026: Machine Rage and Microsoft Kills XBox Social Clubs
Links for the day
Links 17/02/2026: Why OpenClaw is Very Sleazy and Ars Technica Exposed as Hub of LLM Slop (Credibility Destroyed Overnight)
Links for the day
Benj Edwards (Ars Technica) Used Fake Articles to Promote Ponzi Scheme for Conde Nast and Its Client (Marketing)
What Ars Technica and Conde Nast do here helps defraud the general public
Slop Technica: Ars Technica Seems Like Repeat Offender, a Part-Time Slopfarm
The culprits are repeat offenders, but the publisher will never admit this in public
Only One in 50 Saudis Would Use Microsoft for Search, Almost Same as Would Use Russia's Yandex
If statCounter is to be trusted
Microsoft's "AI" Concerns Are All Indian (or Low-Paid Workers Who Work Extra Hours Unpaid)
portraying charlatans and frauds like they're some kind of visionaries and luminaries
Microsoft Turned Bing Into Censorship Machine of China, But Bing Is Pegged at a Mere 2% in Asia, Yandex is Bigger
Expect many Bing layoffs some time soon (like in past years)
Just Like The Register MS, Conde Nast's Ars Technica Has Just Publicly Admitted That It Published Fake Articles (Slop) Made by LLMs About Serious Subjects
Conde Nast might shut Ars Technica down to escape the bad publicity/association
Solicitors Regulation Authority (SRA) Way Too Slow to Respond to Financial Fraud at Law Firms, in Effect Helping Those Law Firms Defraud Many More People (Fleecing Clients)
Who will hold the SRA accountable for this?
Techrights Became a Hub for News That IBM/Red Hat Doesn't Want You to See (and Pays Mainstream Media to Distract From)
the more viciously the notorious organisation attacks the reporter, the greater the interest in what the reporter has to say
EPO's Central Staff Committee on Fourth Technical Meeting, Two Days Before First of (At Least) 4 Winter Strikes at the Second-Largest European Institution
“future orientations on the salary adjustment procedure”
IBM's Collapse Continues, Half of EU Countries to Have Mass Layoffs, "IBM Clearly Disinvests From Europe" Says IBM European Works Council
Recent publication
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Monday, February 16, 2026
IRC logs for Monday, February 16, 2026
Gemini Links 17/02/2026: Alpenglow Industries' Closure and Gemini Server Issues
Links for the day
The Southern California Linux Expo (“SCALE”) or SCALE 23x Becomes Microsoft
It's not supporting the event, it is buying it.
Where Microsoft's Bing Cannot Even Reach 1% "Market Share"
Looking at "I" countries
Microsoft to Focus on Name-Dropping Buzzwords to Distract From Declining Business, IBM RAs (Layoffs) With Staff Stack-Ranked
Calling everything cloud or reclassifying as "AI"
Another EPO Strike One Week From Now, Local Staff Committee Munich to Discuss It This Week
Campinos MIA while Office staff goes on strike at least 4 times
Links 16/02/2026: Barack Obama Responds to Racist Cheeto and Benjamin Mako Hill Studies Online Communities
Links for the day
Gemini Links 16/02/2026: Task Completed by Avoidance and "Playing Again With Akkoma"
Links for the day
Happy Birthday (or Anniversary) to SoylentNews
"Happy Birthday SoylentNews"
Techrights' Architecture
Stability is the main goal
IBM Reduces the Thresholds for Acceptance (and the Salaries)
Are chatbots good enough as IBM staff?
When It Comes to Rust, Keep All the Eyes on the Ball (Technical and Legal Perils, Sustainability Questions)
It's not about security or politics
Linux Foundation Continues Falling Off a Cliff in Geminispace
Gemini Protocol will turn 7 this summer
Links 16/02/2026: cURL’s Daniel Stenberg Asserts That Slop is DDoSing Free Software, But Still Uses a Plagiarism and GPL-Violating Blender (Microsoft GitHub)
Links for the day
The Techrights Community Never Needed Money, Only Goodwill
We accomplish things by a track record of suppressed facts
"AboutCode" is a Microsoft Proxy and Microsoft's Acquisition of the OSI Advances Via OSI Moles
presenting direct evidence anybody can verify
Social Control Media is Just a Digital Weapon
Social control media is not social and not media
They Will Call Smart People "Luddites"
Is society "seeing the light"?
Microsoft Amutable Already Reveals That Its Focus Is Not Linux, It'll Promote "Remote Attestation"
This is basically an attack on Software Freedom, even if they toss around the brand "Linux"
More People in Chad Move to GNU/Linux
Last year we began to see GNU/Linux rising there - a trend which continues this year
Dr. Andy Farnell on How Universities and Culture of Education Got Crushed by "Technofascist Nightmare"
Farnell says he "already soft-quit in [his] mind"
Debt of Broadcom Grew by More Than 50%, Broadcom is Deeper in Debt Than Google
Expect many more cuts
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Sunday, February 15, 2026
IRC logs for Sunday, February 15, 2026