4 ms·
There's some new information released which mentions the github repo name, and since when the vulnerability has existed.
by hackerpain 6y ago
There's some new information released which mentions the github repo name, and since when the vulnerability has existed.
- bulatb 6y agoYeah, this is a less-but-still-misleading follow-up. The password might turn out to be related or might not, but I don't think the added details point either way. This security company's marketing blog is mixing up the facts with speculation. Let's especially be careful not to use it in the "nation state vs. kid in a basement" debate.
- hackerpain 6y agoThe researcher added there may be some certificates exposed in that repo which may have been used to sign the binaries. It's still a relevant update. Especially the information that the repo was archived by Web Archive back in 2018. It's not easy to know the "who" but the how can be speculated and investigated.
- bulatb 6y agoI think I snuck an edit in while you were writing. Sorry! I see where the researcher says it's not impossible he missed a certificate, but not a reason to believe he actually did. The article is unfortunately full of leading questions and reaching speculation.