4 ms·
Why on earth would you be defending this? No one would ever add something like this in good faith.
by peanut_worm 5y ago
Why on earth would you be defending this? No one would ever add something like this in good faith.
- tethys 5y agoDo we know if this was enabled by default? The Spider.com SDK License [0] appears to not allow it. > Partner shall ensure that only Users who have expressly agreed to become nodes will actually be marked by Partner as such (…). [0] https://www.spider.com/sdk-license https://www.spider.com/sdk-license
- olalonde 5y agoDidn't read the whole code but this makes me think it was: https://github.com/d2phap/ImageGlass/commit/31c1b918165c42deb296bad3ae01d7d272e7abfc#diff-59b2b48f6cd92a3c14779ad6e5b54c1ae932a6199aca37507fca4c3010317b79L315 https://github.com/d2phap/ImageGlass/commit/31c1b918165c42de...
- dymk 5y agoThe service was enabled by default. In a later commit he adds an option to opt-out of Spider being enabled.
- anaisbetts 5y agoIf he was adding it in bad faith, why would he put it on GitHub for all to see, rather than building the binaries in a private fork? Seems like this is incompetence / naivete rather than malice.
- dymk 5y agoHe put the code in a commit titled "restructure external dlls" with no reference to what it did, and in other commits includes the string "Spider" (no description of _what_ that does in the title). These weren't added as pull requests where one might expect to review proposed changes, but as direct commits to ~master. It's not uncommon for people to put obfuscated malware into open source code See: hackers putting cryptominers and wallet stealers [0] into compromised NPM packages, or UoM campus being banned from contributing to Linux for backdooring the Linux kernel [1]. [0] https://www.trendmicro.com/vinfo/dk/security/news/cybercrime-and-digital-threats/hacker-infects-node-js-package-to-steal-from-bitcoin-wallets https://www.trendmicro.com/vinfo/dk/security/news/cybercrime... [1] https://www.theverge.com/2021/4/30/22410164/linux-kernel-university-of-minnesota-banned-open-source https://www.theverge.com/2021/4/30/22410164/linux-kernel-uni...