4 ms·
They also used social engineering to disable fuzzing which would have caught the discrepancy: https://github.com/google/oss-fuzz/pull/10667 https://github.com/g
by joshcryer 3y ago
They also used social engineering to disable fuzzing which would have caught the discrepancy: https://github.com/google/oss-fuzz/pull/10667 https://github.com/google/oss-fuzz/pull/10667
- codetrotter 3y agoIt’s pretty funny how a bunch of people come piling reaction emojis onto the comments in the PR, after it has all become publicly known. I’m like.. bro, adding reaction emojis after the fact as if that makes any sort of difference to anything.
- happosai 3y agoHonestly, it's harrasment at this point.
- qudat 3y agoFeels almost like tampering with evidence at a crime scene
- lazide 3y agoIt’s just adding your initials on the tunnel someone famous just died in.
- cqqxo4zV46cp 3y agoThat’s absurd. Elaborate.
- jijijijij 3y agoThat thread has become an online event and obviously lost its original constructive purpose the moment the malicious intent became public. The commenters are not trying to alter history, it's leaving their mark in an historic moment. I mean the "lgtm" aged like milk and the emoji reactions are pretty funny commentary.
- moomoo11 3y agoIs the person Jia who did this PR a malicious actor?
- CSMastermind 3y agoThe person who submitted the PR, JiaT75, is. The person who approved and merged it is not.
- filleokus 3y agoWould it really have caught it?
- formerly_proven 3y agoNo
- pas 3y ago... why?
- filleokus 3y agoDid the artefact produced [0] for fussing even include the backdoored .so? My understanding was that the compromised build-scripts had measures to only run when producing deb/rpms. https://github.com/google/oss-fuzz/blob/5f70676a6c9050b9cb687cdb1543354702a8c757/projects/xz/build.sh https://github.com/google/oss-fuzz/blob/5f70676a6c9050b9cb68...
- ycombinatrix 3y agomy understanding is that fuzzing "caught" the issue by crashing with ifunc disabled but it wouldn't have "caught" the backdoor which uses public key cryptography