> But open sourceness in no way contributed to this being found, it was not in the source code.
Where was it? The explanation I saw included obsfucated code. ?
Where was it? The explanation I saw included obsfucated code. ?
The backdoor consisted of a combination of publicly visible code and binary blob test files available in the project's repository as well as obfuscated build scripts which were contained only in the released tarballs, tucked away, which, nevertheless, were also publicly accessible, decompressable and auditable[1]
in some sense, exact specifics of the attack were discovered because norm of open source is even more open than the gpl-and-co require