2 ms·
I would remind all the people to recompile the build themself, before downloading a random binary and allowing it to access the Slack workspace. But, very inter
by serhack_ 2y ago
I would remind all the people to recompile the build themself, before downloading a random binary and allowing it to access the Slack workspace. But, very interesting project!
- floam 2y agoI’m honestly surprised there aren’t way way more… extremely nefarious straight up trojan data exfil builds out there of all kinds of rando tools posted as like “hey here’s a convenience build I got to compile for toy arch | codesigned for macOS | helpful VM or Docker image | did something sneaky to bypass API rate limits | fixes that one annoying thing YMMV” etc. and posted as comments on HN or anywhere by seemingly helpful nerds, with the web server serving up the evil build 5% of the time or GeoIP’d to the Bay Area. Like it seems like such easy low effort “hacking” why isn’t it more common? Hell even GitHub “Releases” on your fork can also just not match the repo.