4 ms·
I don't really see how anyone can win this challenge (other than how already done). The guy will be super cautious of any pull requests.
by Magnets 10y ago
I don't really see how anyone can win this challenge (other than how already done). The guy will be super cautious of any pull requests.
- schoen 10y agoMaybe there's a way to mislead someone about the content of a pull request (e.g., a race condition in GitHub or some other UI to git, a Unicode rendering bug, a UI that hides or obscures the content of some software comments, a bug in git's merge logic, putting the code into the source of an upstream library that he pulls into his code wholesale...). I actually have another idea which I now think I should try to do, so I won't give the details here.
- tstrimple 10y agoYou could probably hide it pretty effectively during a normal pull request to fix an existing issue. As long as they aren't greping for the string anyhow. If he's going to use tools to to search a PR for the string, you'd have to obfuscate it. There are plenty of string and / or byte array manipulation techniques to sufficiently hide something like this as long as it's masked by an otherwise real PR.
- ultramancool 10y agoYou'd have to rely on a ball of jumbled crap somewhere in the PR though - maybe if they don't wrap lines or something you could slip it in?
- Natanael_L 10y agoI'd be XORing against some existing strings in the code of the same length to obfuscate the content, with some hidden method to invoke the reverse XOR to regenerate this challenge text string.
- Magnets 10y agoThat sounds very difficult to hide
- ultramancool 10y agoSure, hiding it as a basic string is easy. But hiding it in a way that a simple code review won't catch is probably a lot harder.
- Natanael_L 10y agoI think some array manipulation could do it if you're clever enough and don't make it obvious where all of the inputs comes from. So you'd make some particular parameters regenerate the string, and it wouldn't obviously stand out from the normal behavior.
- Magnets 10y agoThe guy is responsible for a small number of low-activity projects, he's going to go over any new pull requests with a fine tooth comb
- infogulch 10y agoIf he's using github to merge pull requests, you might be able to hide it in the details section (2nd+ line) of one of several commit strings. People might check the commits, but github usually hides all but the first commit message line. Not sure if this would count as 'part of the software project' though.