Bonum Certa Men Certa

Edward Brocklesby (ejb) & Debian: Hacking expulsion cover-up in proximity to Oxford and GCHQ

posted by Roy Schestowitz on Jun 06, 2024,
updated Jun 24, 2024

Reprinted with permission from Daniel Pocock.

As written previously, I don't believe that Debian Developers can be expelled as such because the relationship between us is a relation of joint authorship.

Nonetheless, from time to time it is necessary to remove somebody's access to Debian infrastructure due to concerns about their integrity and other poor behavior. The first case of this was Shaya Potter, for WaReZ operations.

There is a pattern that has become very easy to see: if somebody is expelled in a very public manner then it is due to backstabbing by the corrupt leadership. The expulsion of Jacob Appelbaum based on falsified harassment claims was the most prominent example of backstabbing. On the other hand, when the leadership has failed to protect the security of the Debian distribution, the whole affair gets covered up. The expelled person is free to go elsewhere.

The most dramatic case that has been hidden from the public is that of Edward Brocklesby (ejb). Looking at Shaya Potter, we could follow his career path after his departure from Debian. Edward Brocklesby simply disappeared into obscurity. Did he even exist at all or was Edward Brocklesby a fake name for somebody who we don't really know?

The second notable point about the case of Edward Brocklesby is the list of packages he was maintaining. His package list was discussed after his exclusion:

Subject: Re: ejb's old packages--who want to adopt them?
Date: Tue, 25 Apr 2000 10:05:15 +0100
From: Steve McIntyre <stevem@chiark.greenend.org.uk>
To: Anthony Fok <foka@ualberta.ca>
CC: debian-private@lists.debian.org

On Tue, Apr 25, 2000 at 09:14:42AM +0100, Anthony Fok wrote: > >According to Joey's earlier post, here are the packages that ejb left >behind: > > archie, csh, eggdrop, gcc-m68k-gnu, hx, mh, mh-paper, mig-m68k-gnu, > pmake, sac, simh, simh-rsts-images, simh-unix-images, ssh2 > >Hope we can all pitch in and pick up one or two of them. Otherwise, >they'd have to be orphaned -> debian-qa, definitely before potato is >out, otherwise the bug reports would be unattended to.
I'll take pmake; we occasionally use it at work and it would be painful to lose it.
-- Steve McIntyre, Allstor Software smcintyr@allstor-sw.co.uk My PC page "Can't keep my eyes from the circling sky, "Tongue-tied & twisted, Just an earth-bound misfit, I..."

While discussing ejb's packages, nobody seemed to notice that these are just the packages that a serious bad guy would want to put backdoors into: shells, compilers and even the ssh2 package. There was incredible complacency about this.

In hindsight, it seems even more odd that the person maintaining those packages has simply vanished. In other words, the person maintaining those packages for a number of years may have been using a fake name.

This is the reality of security on Debian: the package maintainers may be fast at copying security patches from upstream and getting them released but they can't really understand what they are looking at. By excluding talented developers and dumbing down with groupthink, they reduce the amount of adult scrutiny on situations like this.

The failure of anybody to notice the risk of backdoors in those binaries is one of many glaring oversights in the EJB case.

Another thing people failed to notice is that Brocklesby was living in close proximity to the A40, that is the road from Oxford to the GCHQ office at Cheltenham. GCHQ doesn't publish a list of their employees in the free and open source software space, nonetheless, it is widely accepted that such people exist.

Edward J Brocklesby, Debian, Una P Brocklesby, Oxford

The IETF records show us he was interested in the development of standards for IRC.

His interest in standards or any other public activity seems to cease completely within a short time of the discovery of his activities around Debian.

The next big red flag in the way Debian handled the Edward Brocklesby affair is that they failed to immediately restrict his access to Debian infrastructure. For some weeks they engaged in a debate with him on the debian-private (widely leaked) secret cubby house. He almost fooled them to allow him to keep his access privileges.

The BBC obtained a secret tape recording of Kim Philby talking to Stasi agents.

In 1963, an MI6 colleague came to confront him with new evidence pointing to his work for the Soviets.

Philby bluffed and stalled.

...

Philby finishes with one piece of advice to the spies gathered before him that had served him well: never confess.

"If they confront you with a document with your own handwriting then it's a forgery - just deny everything…

"They interrogated me to break my nerve and force me to confess.

"And all I had to do really was keep my nerve. So my advice to you is to tell all your agents that they are never to confess."

Looking through debian-private, we can see Edward Brocklesby buying time. Philby was not the only one to use these tactics.

Ireland needs a high-level expert on cybersecurity in the European Parliament. Please see my nomination and promote it as widely as possible as we count down to the vote this Friday, 7 June.

GCHQ, Chelthenham

More news and policy statements regarding my campaign for European Parliament:

Please print my brochure if you want Ireland to change

Other Recent Techrights' Posts

Cybersecurity Does Not Mean Asking Microsoft for Permission to Boot
There were very good and timely reasons to speak about the matter, including impending antitrust complaints against Microsoft
 
Microsoft at 50 Follows the General Trajectory of Skype
How many years does Microsoft have left before payroll becomes impossible?
A Year After a Microsofter Took Over The Register MS It is Effectively a Content Farm With News as a 'Side Dish'
This is not journalism, this is spam
IBM Pays the Media and Cons Some 'Journalists' Into Participating in "Quantum" Spam
"The Boy Who Cried Wolf"
You Don't Need an 'App' for Your Birdhouse (Slopfondlers Come for Birds)
That they sell those things as "AI" really says a lot about how dishonest slopfondlers really are
SLAPP Censorship - Part 113 Out of 200: The United Kingdom is Not Turkey
Turkey is ranked almost worst in the Western World for press freedom
Links 21/06/2026: Bots from Alibaba Do Harm and Many Xbox Games Are Being Cancelled
Links for the day
5 Years After Release of Vista 11 Not Even One in 5 People Use It (in the US)
It doesn't look like Vista 11 will ever be adopted like prior versions and announcing a Vista 12 will mostly upset companies/organisations that only recently "upgraded" to 11
Gemini Links 21/06/2026: Boca Raton, Perfect Summer Day, and LLM Doing Things Poorly
Links for the day
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Saturday, June 20, 2026
IRC logs for Saturday, June 20, 2026
Microsoft Insiders - Not Limited to XBox - Expect a 'Bloodbath' (Their Own Word)
This isn't limited to XBox
Reports of "PIP" as Means of Mass Layoffs at IBM This Year
some insights into the PIPs
SLAPP Censorship - Part 112 Out of 200: Strangles Women, Then Refuses to Even Attend Any of His Own Hearings About It
It is meanwhile very apparent that Brett Wilson LLP is becoming a "mench sphere"
Gemini Links 20/06/2026: "There Was Never Supposed to Be a Camera" and "What Is A Programming Language"?
Links for the day
Geminispace Reaches Its 8th Year, Today It Has Turned 7
Gemini Protocol 'went live' 7 years ago, just before the COVID-19 pandemic
Links 20/06/2026: "Full Page Paralysis" and "Hopes For Xbox’s Future Might Be Over Before It Even Begins"
Links for the day
European Patent Office's (EPO) Strikes "at a Scale not Seen Since Battistelli", European Patent Grants Down by Over 25% in Past 3 Months
The actions are effective
Real Security Elusive, Microsoft Layoffs to Coincide With Certificate Apocalypse
July 1
Links 20/06/2026: Microsoft's "Year of Shame" and "Feed the Writers"
Links for the day
2026 is a Year of Strikes at the European Patent Office (EPO)
As it stands at the moment, to many people the EPO represents crime, not law
Web Browsers Are Technically Bloatware (No Matter What Runs in Them)
Don't make it a society that shames people into using a Web browser where none should be needed
Fedora Has Changed a Lot Since I Last Used It (IBM Dominates Almost Everything, IBM Agenda Displaces Community Goals)
"It is effectively 100% run by Red Hat/IBM employed people... even when they are community-elected representatives."
Andy (Cyber Show) on His Teacher Who "Squeezed Every Last Drop Out of Life, With Gratitude, Humility, Generosity and Mettle"
Some call them "eccentric" and are dismissive about what they have to offer
Only 1.5% Oppose the European Patent Office's (EPO) Strikes and Other Industrial Actions Until 2027
Among those polled/surveyed (in a ballot)
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Friday, June 19, 2026
IRC logs for Friday, June 19, 2026
Gopher/Gemini Links 20/06/2026: Slop With Tcl/Tk and Nokia 770 Perishes
Links for the day
SLAPP Censorship - Part 111 Out of 200: Garrett and Graveley (the Latter Arrested for Strangling Women) Keep Ousting Their Collaboration in Litigation, Lawfare in a Foreign Continent
it's not law, it's just warfare disguised as "law"
European Patent Office (EPO) Series: Lobbying in Lisbon...
reappointment campaign lobbying has not been restricted to the "home front" in Portugal
Slop Making Its Way Into Terms Where It Does Not Belong
Hopefully by year's end Google News can successfully cull (and deprive of traffic) almost all slopfarms
Links 19/06/2026: Microsoft Patent Troll Intellectual Ventures in Europe, "World Cup of Internet Resilience"
Links for the day
Links 19/06/2026: Salesforce Data Thefts and GAFAM's Conspiracy Theories That Data Center Opposition is a Foreign Plot
Links for the day
Links 19/06/2026: The Retweeting Class and Data Centres as National Security Risk
Links for the day
Don't Attack the Wives (or Spouses) of Pundits/Activists/Journalists
We will be writing several series about this in the future
Society Will Only Improve Owing to People Who Push Boundaries
Push boundaries with ideas and facts, not with forbidden language
Internet Relay Chat (Shorthand IRC) is Still Growing
Contrariwise, social control media is waning
The Register MS Published a New Page With "AI" 21 Times in It. It Was Paid SPAM.
The former editor of the The Register MS admitted to me (directly) that he knew all this "AI" stuff was stupid hype
Murdoch's Wall Street Journal (WSJ) Associates Dependence on a Ponzi Scheme With "the Future"
Those ludicrous ads (disguised as rankings) from WSJ deserve scorn and ridicule
The XBox Story is Still Fast-Developing, the Layoffs Are Confirmed to be Happening Already (Mid-June), Just Not "Officially"
Workers have Microsoft have long braced for what is happening this summer and will accelerate further in two weeks' time
Fake News From Rupert Murdoch's WSJ Could Not Keep IBM From Sinking
"2026 Best Companies for the Future"?
To GNU, AV2 Adoption May be a Year If Not Years Away
The leap between versions means that there is fertile ground for incompatibilities
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Thursday, June 18, 2026
IRC logs for Thursday, June 18, 2026
Gemini Links 19/06/2026: "Born and Raised by the Internet", Fifteen Years in Gopher
Links for the day