Bonum Certa Men Certa

British Intelligence, GCHQ, Oxford & Debian conspiracy theories, Edward & Una Brocklesby fact checking

posted by Roy Schestowitz on Jun 07, 2024

Reprinted with permission from Daniel Pocock.

At 21:00 UTC on 5 June 2024, I published the first disclosure about the secret expulsion of Edward Brocklesby from Debian.

A few hours later and some of the rogue elements at Debian started spreading more defamation about me. It looks like the disclosure about Debian's lack of competence for security has struck a chord and people need to look more deeply at this particular case.

As the elections are in progress the Internet is full of conspiracy theories right now. An Irish election candidate poking fun at British Intelligence should be viewed with scepticism and fact checked very carefully.

Therefore, I will simply link to some of the facts and leave it up to the community to draw conclusions.

The first thing to note is that GCHQ is reknowned for their use of puzzles. For example, they have published puzzles as a strategy for recruiting people. The stuff about GCHQ using puzzles is widely known and published by GCHQ themselves and it is also described by the press in the UK and abroad. From RTE, Ireland's national broadcaster:

An Irish code-breaker, along with two others, has proved he is almost a match for the UK's national intelligence and security agency by winning its Christmas card cryptography challenge.

One of the first things that people found about Edward Brocklesby is a web page about Chess scores from the Oxford Cambridge Varsity competition in London. The games took place in 1935 and 1936. The page tells us that this particular Edward Brocklesby was born 29 April 1914 and died 9 December 2004. Clicking through the pages we find a link to another article telling us this was Edward Willingham Brocklesby who was originally associated with Cambridge but later went to Oxford. However, the middle initial doesn't match Edward J Brocklesby in Debian.

In practice, we know that people are not always using their real names in Debian and free software. People may tweak their initials or use pseudonyms. For example, the woman using the name "cryptie" in the FSFE subsequently had to reveal she was a French Government employee moving to a job at the European Union. She admitted her real name is Amandine Jambert and her conflict of interest and resigned.

It is not uncommon for people to commit identity fraud by using the names of other real people, whether alive or dead, rather than making up names that are entirely fictitious. Using the name of somebody who is elderly or somebody with a disability is a special case.

The name of the FSFE is itself an example of identity fraud because it is confusingly similar to the real FSF. This type of thing is very common in open source software.

People found a HP Enterprise Forum account for Edward Brocklesby. The account was created 12 May 2003 and last used on 21 June 2011. It is not uncommon for accounts in online forums to be hacked so even if the account was created by the "real" Edward Brocklesby from Debian, it may have been used by another person in later years.

The 192.com directory service finds both Edward Brocklesby and Una Brocklesby living at the same address that is used in the document submitted to the IETF. 192.com tells us they are on the electoral roll at that address at the same time and both of them were removed from the electoral roll in 2002, not long after the Debian expulsion.

There are various reasons somebody could be removed from the electoral roll. They might die, they might move to another country or they might have simply moved to another address and decided not to enroll again. However, there are also special cases for police and military employees to have their status on the electoral roll protected.

There are many regular police units who have engaged in undercover activities. It would be wrong to assume every person using a fake name in Debian is with GCHQ or the NSA. London's Met Police issues with the undercover officer Mark Kennedy have been widely documented. It wouldn't be a big surprise to find people like this operating in free software communities.

There is an Una Brocklesby account on Trustpilot and she is in the UK and active between 2017 and 2024.

In the St Hugh's College, Oxford Chronicle of 1998-1999, we find that Una Brocklesby is listed in the staff section as a Finance Assistant.

Una Brocklesby, St Hugh's College, Oxford

This adds weight to the idea that they were either using their real names or they were very sophisticated deep cover agents, living as a couple, having paperwork and jobs.

Looking at Edward Brocklesby's activities in the debian-private cubby house over the years, we find most of his messages concern security topics. He appears to have various email addresses on different networks.

Subject: www.tr.debian.org security
Date: Sun, 6 Jun 1999 17:26:49 +0000
From: Edward Brocklesby <ejb@fairport.styx.uk.eu.org>
To: debian-private@lists.debian.org

Hi,
A user on #shells was offering to trade www.tr.debian.org. It might be an idea to check security on this host.
-- Edward Brocklesby System Administrator ejb@styx.uk.eu.org Styx Public Access Unix System http://www.styx.uk.eu.org

and in this second example, Brocklesby signs off with Diolch, which is Welsh.

Subject: Re: another security hole
Date: Sun, 11 Jul 1999 21:55:00 +0000
From: Edward Brocklesby <ejb@incest.dhis.org>
To: Josip Rodin <joy@cibalia.gkvk.hr>
CC: Grzegorz Stelmaszek <greg@tenet.pl>, Josip Rodin <jrodin@public.srce.hr>, security@debian.org, debian-devel@lists.debian.org, 39395@bugs.debian.org

On Sun, Jul 11, 1999 at 05:21:02PM +0200, Josip Rodin wrote: > > > Note bene - AIK debian still uses unpatched version of pine, so there is > > easy way to run any command via it IF you know to whom send an email. > > File a bug, if it already isn't reported.
I filed a bug on this. In the end, we decided it was not a pine bug, but in fact some other program was inserting the bad stuff.
(Bug#33099, BTW)
Diolch, Edward.

The bug report gives us another email address and permutation of the name:

From unknown Fri Jun 07 17:33:16 2024
Received: (at submit) by bugs.debian.org; 8 Feb 1999 20:12:40 +0000
Received: (qmail 26297 invoked from network); 8 Feb 1999 20:12:39 -0000
Received: from finch-post-10.mail.demon.net (HELO post.mail.demon.net) (194.217.242.38)
  by master.debian.org with SMTP; 8 Feb 1999 20:12:39 -0000
Received: from [212.228.198.242] (helo=klamath)
        by post.mail.demon.net with esmtp (Exim 2.12 #1)
        id 109x2j-0005B7-00
        for submit@bugs.debian.org; Mon, 8 Feb 1999 20:12:30 +0000
Received: by klamath.lilithfair.org
        via sendmail from stdin
        id <m109x2g-0005KHC@klamath> (Debian Smail3.2.0.102)
        for submit@bugs.debian.org; Mon, 8 Feb 1999 20:12:26 +0000 (GMT)
Message-ID: <19990208201225.A1194@klamath.lilithfair.org>
Date: Mon, 8 Feb 1999 20:12:25 +0000
From: "Edward John M. Brocklesby" <ejb@klamath.lilithfair.org>
To: submit@bugs.debian.org
Subject: PINE allows remote users to execute commands as the user running PINE, by sending an email
Mime-Version: 1.0
Content-Type: text/plain; charset=us-ascii
X-Mailer: Mutt 0.91.1i
X-Operating-System: Linux klamath 2.1.131
X-No-Archive: yes

Package: pine396-src Version: 2 Severity: critical
PINE does not handle the ` character correctly.
Take a look at this email:
************************** MIME MESSAGE FOLLOWS ************************** From: Attacker <attacker@eleet.net> To: Victim <victim@somewhere.net> Subject: Happy birthday ... MIME-Version: 1.0 Content-Type: MULTIPART/MIXED; BOUNDARY="8323328-235065145-918425607=:319"
--8323328-235065145-918425607=:319 Content-Type: TEXT/PLAIN; charset='US-ASCII'
Make a wish...
--8323328-235065145-918425607=:319 Content-Type: TEXT/PLAIN; charset=``touch${IFS}ME``; name="logexec.c" Content-Transfer-Encoding: BASE64 Content-Description: wish Content-Disposition: attachment; filename="wish.c"
...it could be your last. *************************** MIME MESSAGE ENDS ***************************
When pine sees this, it expands:
text/plain; shownonascii iso-8859-1 %s; test=test "`echo %{charset} | tr '[A-Z]' '[a-z]'`" = iso-8859-1; copiousoutput
to this:
[...] execve </bin/sh> (sh) (-c) (test "`echo '``touch${IFS}ME``' | tr '[A-Z]' '[a-z]'`" = iso-8859-1)
This allows any command to be executed. The following patch works against PINE 4.10, it may require modification to compile against slink's version:
--- pine4.10.orig/pine/mailcap.c Wed Nov 18 13:00:15 1998 +++ pine4.10/pine/mailcap.c Mon Feb 8 09:17:46 1999 @@ -905,14 +905,18 @@ * have to put those outside of the single quotes. * (The parm+1000 nonsense is to protect against * malicious mail trying to overlow our buffer.) + * + * TCH - Change 2/8/1999 + * Also quote the ` slash to prevent execution +of arbirtrary code */ for(p = parm; *p && p < parm+1000; p++){ - if(*p == '\''){ + if((*p == '\'')||(*p=='`')){ *to++ = '\''; /* closing quote */ *to++ = '\\'; - *to++ = '\''; /* below will be opening quote */ - } - *to++ = *p; + *to++ = *p; /* quoted character */ + *to++ = '\''; /* opening quote */ + } else + *to++ = *p; }
fs_give((void **) &parm); @@ -954,7 +958,7 @@ */ if(!used_tmp_file && tmp_file) sprintf(to, MC_ADD_TMP, tmp_file); - + return(cpystr(tmp_20k_buf)); }

Other Recent Techrights' Posts

Doing My Share to Tackle Online Slop and SPAM
Trying my best to 'fix' the Web
Slopwatch: Fakes, FUD, Duplicates, and Charlatans Galore
The Web as we once know it is collapsing. Some opportunists try to replace it with low-quality slop.
The Register UK Seems to Have Become American and Management is Changing (Microsofter as Editor in Chief)
The Register 'UK' is now controlled by the Directions on Microsoft guy
Microsoft Windows Lost 400 Million Users in a Few Years, Why Does The Register Double Down on Windows With New US Editor?
days ago they hired a new US editor
Links 25/07/2025: NOAA Cuts Endanger Lives, "Europe's Self Inflicted Cloud Crisis"
Links for the day
 
Links 26/07/2025: 50 Percent Tariffs in Amazon, Dying Intel Offloads Network and Edge Group (NEX)
Links for the day
Blaming Programming Languages for Users' and Developers' Bad Practices
That's like blaming cars for drivers who crash into things
Many People Still Read Techrights Because It Says the Truth, Produces Evidence, and Does Not Self-Censor
Unlike so many other sites
The Register is Desperate for Money, According to The Register
I decided to check how they're doing as a business
Microsoft Finally Finds a Use Case for Slop?
Create low-quality chaff to shift the media's attention?
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Friday, July 25, 2025
IRC logs for Friday, July 25, 2025
For Libel Reform One Must First Bring (or Raise) Awareness to the Issues and Their Magnitude
I myself know, from personal experience
Links 26/07/2025: Rationed Meals in the US and TikTok Repels Investments (Too Toxic)
Links for the day
Gemini Links 26/07/2025: "Bloody Google" and New People in Geminispace
Links for the day
Response to Solderpunk (Father of Gemini Protocol) About the Gemini Community
Solderpunk responds to non-sequitur
HTML and the Web Used to be Something a Child Could Learn, "Modern" Web is a Puzzle of Frameworks, Bloat, and Worse
When the Web was more like Gemini Protocol
New US Editor in The Register is 84% Microsoft/Windows Booster
It'll be worrying if it carries on like this
Links 25/07/2025: Slop Blunders and China Has Code of Conduct for Lawmakers in HK
Links for the day
Gemini Links 25/07/2025: Some Books and Babies and Capital
Links for the day
They Try to Lecture Us on Ethics
They even removed "master" from Microsoft GitHub
The Future of the Web is One Rendering Engine or 'Flavours' of Chrome
The future of the Web does not look bright at all
Best Sites Are Not Optimised for Any Browser, They Work Equally Well With All of Them
Red Hat (IBM) is making rubbish sites
YouTube is a Spamfarm, Slopfarm, and Clickfarm (a Lot of Numbers There Are Fake)
Those who don't fake look unpopular and unimportant
We Don't Do JavaScript and Pages Are Small
Thankfully Gemini Protocol has nothing like JavaScript
'Tech' is Not Technology
Some people use terms like 'Old Tech'
IBM's Debt Rose by Almost 10 Billion Dollars in the Past 6 Months Alone
The "hey hi" circus is coming to an end
Yes, Master
Gaslighting by actual racists
Microsoft Bribes and Buys Politicians to Tell Europe What to Do About Free Software (Which It's Attacking)
Microsoft: we speak for the thing that we are attacking! Follow the money...
Making Backups Quickly and Reliably
Backups are imperative, more so in an age of uncertainty, unpredictable weather, and worsening standards (quality of products going down while prices go up)
Techrights Investigation: Estimating the Point in Time LinuxIac Turned Into LLM Slop (Part of the Time)
Bobby Borisov got lazy
10th Month, Ten Weeks From Now, at Ten AM
In Wentworth Institute of Technology in Boston
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Thursday, July 24, 2025
IRC logs for Thursday, July 24, 2025
A Nadella Memo Distracts From Microsoft's Cheapening Of the Workforce
Right now the "MSM" (mainstream media) is flooded/overwhelmed by garbage pieces that relay lies for Nadella
Vanishing Faces of GNU/Linux
Free software projects do not depend on any one person or company to still exist
Microsoft Says It Lost 400 Million Windows Users, Now It's Waiting for GNU/Linux to Stop Booting on 'Old' PCs
When it comes to Windows, Microsoft is fully aware of the issue and statements it made earlier this summer suggest it lost 400 million Windows users
Slopwatch: LinuxTechLab, linuxsecurity.com, LinuxIac, and More
Also: The Register's Microsoft agenda (new editor)
Gemini Links 25/07/2025: Gemtext Aware Titan Editor and Gemini Protocol Comeback
Links for the day
Links 24/07/2025: Convicted Felon Quits UNESCO, "Vibe Coding Goes Wrong", and Signalgate Gets Worse
Links for the day
Gemini Links 24/07/2025: Forgejo Woes and Smolnet Directory Week
Links for the day
Misinformation is Not Intelligence
It's low-grade plagiarism and it fails to show any signs of intelligence
Links 24/07/2025: Storage Tapes Still Kicking, Windows TCO 'on Steroids' (Microsoft-Induced Catastrophes)
Links for the day
Bobby Borisov (LinuxIac) Has Apparently Begun Experimenting With LLM Slop, So We Cannot Trust LinuxIac Anymore
So did LinuxIac become a slopfarm? Maybe not yet, but it's getting there
Informa TechTarget's ITProToday is Becoming a Slopfarm Generated by Microsoft Chatbots
Busted.
'Tech' Gimmicks Are for Advertising, Not for Usability
In the case of Microsoft, they latched onto slop
BetaNews Sacked Brian Fagioli and Deleted His Comments, But He Still Tries to Use the "BetaNews" Brand for Self-Affirmation
Fagioli takes the work of other people
[Meme] Hard to Be a Better Person?
Sooner or later they'll realise that for each pound I spend they need to spend about 1,000 times more
The LLM Con Artists Are Highly Destructive
Who will ever be held accountable for this scam?
Too Bribed by Microsoft to Move to Free Software?
Microsoft lies and Microsoft bribery (in politics)
New US Editor for The Register is a Microsoft Booster
"Avram Piltch has served as US editor for The Register since July 2025."
Microsoft Hiring European Politicians is Another Form of Bribery; There Should be a European Investigation
When Microsoft bribed people in Europe for OOXML (there's no denying this!) a European government delegate said that Microsoft operated like a cult
Reda Demanded That FSF Removes Its Founder, Now Reda Works Directly for Microsoft
A sellout and a traitor, first working for GAFAM, now Microsoft
PCLinuxOS is Raising Money to Support Development After Fire Incident at the Host
PCLinuxOS has not had announcements lately
Speed of the Site Should be Better Now
The "bot attacks" impact the speed of the sister site too
Getting More From AnalogNowhere
Recently we used many images from AnalogNowhere
Microsoft, Microsofters and 'Secure' Boot Shills Already Storming the LWN Report About Expiring Certificate, Shooting the Messenger
LWN has clearly stuck a nerve
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Wednesday, July 23, 2025
IRC logs for Wednesday, July 23, 2025
Disable "Secure" Boot Today (the Only Better Time to Do So Was Yesterday)
Don't trust anything Red Hat tells you about security
Links 23/07/2025: Windows Killed Company After 150+ Years, US Government Mimics Russia's Attacks on the Media
Links for the day
Freedom Generally Wins at the End, History Shows (But It's Constantly Attacked, Too)
At the moment people realise "Linux" (e.g. Android) isn't enough to guarantee any freedoms
Over 3 Months Later Brett Wilson LLP Still Unable to Recruit a Media Lawyer?
"Immediate start", but not found... still unfilled