3 ms·
A supply chain attack to get a backdoor into curl wouldn't involve any of the methods he describes in his blog post, it would involve putting the backdoor into
by mixologic 6y ago
A supply chain attack to get a backdoor into curl wouldn't involve any of the methods he describes in his blog post, it would involve putting the backdoor into one of the dependencies that curl uses such that when curl is compiled using the tainted lib, you end up with a backdoored curl.
Are there any libs in https://github.com/curl/curl/blob/master/configure.ac https://github.com/curl/curl/blob/master/configure.ac that do not have the same level of rigor in testing that curl does?
Getting a backdoor into curl would mean seeking out the weakest link in the dependency chain.
- guipsp 6y agoThe blog post assumes that curl wouldn't be the primary target (fair, almost no end-user uses curl directly), which would make an attack on curl a supply chain attack.