4 ms·
> The only way this discovery would help the hacker, is if they intended to force a security audit of the karma system and/or the move to GitHub. I agree. Of c
by kenmacd 6y ago
> The only way this discovery would help the hacker, is if they intended to force a security audit of the karma system and/or the move to GitHub.
I agree. Of course I can't be sure of anything here, but to me this commit seems suggestive that there's other injected code somewhere since mid 2017.
You also make a good point on attribution. I had considered that too and if not wanting to take credit could tell us anything about the author.
For example say you were an intelligence agency that knew about this access and knew it was being used by an enemy. Perhaps you couldn't let php know about the vulnerability without exposing that you had access to other data allowing you to know about it. Creating this commit could be a way to share knowledge without it being known where/how it was found.
Of course that's all wild speculation.