Hacker News new | past | comments | ask | show | jobs | submit login

Another analysis locates Jia in Eastern Europe: https://rheaeve.substack.com/p/xz-backdoor-times-damned-time...

But I would like to see analysis of timestamp of GitHub events (like PRs and comments timestamps) which are harder to fake.




It's a nice analysis but he misses the fact that the Eastern Europe timezone doesn't match office hours, in particular it'd mean he worked around evenings primarily (see this graph https://files.catbox.moe/4itspl.png)

I had noticed UTC+0300 commits in the repository under his name but I believed they might have been simply committed by the main Finnish maintainer who is in the UTC+0300 timezone.

> But I would like to see analysis of timestamp of GitHub events (like PRs and comments timestamps) which are harder to fake.

I doubt the git commit timestamps are faked, since actually faking them is somewhat difficult to do consistently (you would time travel frequently). I don't think there is some kind of github API for this, however from what I've seen they seem to match up with the same work timespan you see in the commit timestamps.


> I had noticed UTC+0300 commits in the repository under his name but I believed they might have been simply committed by the main Finnish maintainer who is in the UTC+0300 timezone.

There was this one though where they are the author and committer... one in +0300, the other in +0800:

  commit 3d1fdddf92321b516d55651888b9c669e254634e
  Author:     Jia Tan <jiat0218@gmail.com>
  AuthorDate: Tue Jun 27 17:27:09 2023 +0300
  Commit:     Jia Tan <jiat0218@gmail.com>
  CommitDate: Tue Jun 27 23:56:06 2023 +0800
The time between writing the file and the commit is 89 minutes.


You can find the GitHub events here, I compiled them into CSVs.

https://github.com/emirkmo/xz-backdoor-github

I literally run a git hook that fixes my commit times so I don’t look like a freak to my coworkers making commits at 3am, I think an actor of this caliber would too, so I would bet the git commit times are highly choreographed.


FYI, the Australian comment is wrong, WA (which uses UTC+8) does not DST (there's a party to add it, and multiple referenda which failed to add it), given ASIS is in Canberra (as far as we know ;)), it probably wasn't them.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: