One of the more interesting graphics I've seen regarding the XZ backdoor is a representation of Jia Tan's commits over time. Notice how the commits in question were done well outside the normal times this user committed code in the past.

Does this lend credence to the notion that somehow the Jia Tan account was hijacked? Maybe. Or maybe it just means the attackers got sloppy at the tail end of a 2 year op for unknown reasons, like they were up against a hard deadline that was tied to something happening IRL.

I'm curious what the prevailing theory is here.

@briankrebs If the account was hacked, Jia Tan would still be around, proclaiming loudly "hey, it wasn't me, honest". The fact that he has disappeared, means that he knew perfectly well what was happening.

The out-of-character commits probably reflect the time when he forgot to set the time zone to UTC+8 and remained on his "native" time zone of UTC+2.

And, yes, he *was* on a deadline. The systemd people were about to introduce a change that would have prevented the backdoor from working.

@bontchev @briankrebs Or Jia is going to come back from vacation to a hacked account and a *very* full inbox. 😆