oss-sec mailing list archives

Re: Analysis on who is Jia Tan, and who he could work for, reading xz.git


From: Chris Down <chris () chrisdown name>
Date: Wed, 10 Apr 2024 17:32:57 +0100

I do not think that oss-security is a good location for an identity witch hunt, this feels like the wrong place.

Anyway, none of those timestamps are validated, they just come from git. Any even slightly competent security agency is going to have obscured them, so analysis of them likely just directly plays into their hands.

Slightly more difficult (although of course not impossible) to obscure is the actual time of work based on time of receipt by other parties, but I certainly wouldn't do analysis on unverified timezones.

Attachment: signature.asc
Description:


Current thread: