More social engineering attacks on open source projects observed | Computer Weekly
Summary
Members should also be aware of pull requests (PRs) that contain blobs as artifacts – the XX backdoor was a file that wasn’t human readable, not source code; intentionally obfuscated or hard to understand source code; security issues that seem to escalate slowly – the XZ attack started with a relatively innocuous test amendment; deviation from typical project compile, build and deployment procedures; and a false sense of urgency, particularly if someone appears to be trying to convince a maintainer to bypass a control or speed up a review. “These social engineering attacks are exploiting the sense of duty that maintainers have with their project and community in order to manipulate them,” wrote Bender Ginn and Arasaratnam. Interactions that create self-doubt, feelings of inadequacy, of not doing enough for the project, etcetera, might be part of a social engineering attack.” Social engineering attacks can be difficult to detect or protect against via programmatic means as they prey on human emotions and trust, so in the short term, it is also important to share as much information about possible suspicious activity as possible, without shame or judgment, so that community members can learn protective strategies. • During her Black Hat USA 2023 keynote, the acting national cyber director said the White House wants to develop realistic policies to improve the security of open source software. • CISA has announced a number of actions to help secure the global open source ecosystem, as leading package repositories including the Python and Rust foundations advance their own initiatives.