<!-- mobian-agent-page publisher="dailydev" canonical="https://daily.dev/posts/daniel-haxx-se-besdttbr0" -->

---
title: daniel.haxx.se | daily.dev
description: This post discusses how to verify the integrity of the curl package, including checking for backdoors, binary blobs, and hidden payloads in tarballs. It also...
canonical: https://daily.dev/posts/daniel-haxx-se-besdttbr0
twitter:card: summary_large_image
twitter:site: @dailydotdev
og:type: website
og:site_name: daily.dev
og:title: daniel.haxx.se | daily.dev
og:description: This post discusses how to verify the integrity of the curl package, including checking for backdoors, binary blobs, and hidden payloads in tarballs. It also...
og:url: https://daily.dev/posts/daniel-haxx-se-besdttbr0
og:image: https://api.daily.dev/og/posts/bEsDtTBR0.png
og:image:alt: daniel.haxx.se
og:image:width: 1200
og:image:height: 630
og:locale: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# daniel.haxx.se

**[Lobsters](https://daily.dev/sources/lobsters)** · 6 min read · 2 upvotes · 0 comments

## Summary

This post discusses how to verify the integrity of the curl package, including checking for backdoors, binary blobs, and hidden payloads in tarballs. It also highlights the importance of signed tarballs and commits, as well as the acceptance of contributions from anonymous and pseudonymous contributors. The post concludes by emphasizing the need to focus on finding security vulnerabilities in curl rather than attempting to plant backdoors.

## Full article

daily.dev links to this article rather than hosting it. Read it at the original source: <https://daniel.haxx.se/blog/2024/04/10/verified-curl/>

---

Tags: [#security](https://daily.dev/tags/security), [#cyber](https://daily.dev/tags/cyber), [#curl](https://daily.dev/tags/curl)

[View this post on daily.dev](https://daily.dev/posts/daniel-haxx-se-besdttbr0)

```json
{"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://daily.dev/#organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180},"sameAs":["https://twitter.com/dailydotdev","https://github.com/dailydotdev","https://www.linkedin.com/company/daily-dev-ltd"]},{"@type":"WebSite","@id":"https://daily.dev/#website","url":"https://daily.dev","name":"daily.dev","publisher":{"@id":"https://daily.dev/#organization"},"potentialAction":{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https://daily.dev/search?q={search_term_string}"},"query-input":"required name=search_term_string"}}]}
{"@context":"https://schema.org","@type":"TechArticle","headline":"daniel.haxx.se","url":"https://daily.dev/posts/daniel-haxx-se-besdttbr0","mainEntityOfPage":{"@type":"WebPage","@id":"https://daily.dev/posts/daniel-haxx-se-besdttbr0"},"datePublished":"2024-04-10T15:21:17.729Z","dateModified":"2024-05-09T08:43:33.910Z","description":"This post discusses how to verify the integrity of the curl package, including checking for backdoors, binary blobs, and hidden payloads in tarballs. It also...","image":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/acb1f786f8f6dfba2b93bc8094bb49c2?_a=AQAEufR","thumbnailUrl":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/acb1f786f8f6dfba2b93bc8094bb49c2?_a=AQAEufR","isAccessibleForFree":true,"articleSection":"Lobsters","inLanguage":"en","publisher":{"@type":"Organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180}},"author":{"@type":"Organization","name":"Lobsters","logo":"https://media.daily.dev/image/upload/s--tl8v_Fku--/f_auto,t_logo/v1698841318/logos/lobste.jpg","url":"https://daily.dev/sources/lobsters"},"commentCount":0,"discussionUrl":"https://daily.dev/posts/daniel-haxx-se-besdttbr0","interactionStatistic":[{"@type":"InteractionCounter","interactionType":{"@type":"LikeAction"},"userInteractionCount":2},{"@type":"InteractionCounter","interactionType":{"@type":"CommentAction"},"userInteractionCount":0}],"keywords":"security,cyber,curl","timeRequired":"PT6M"}
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://daily.dev"},{"@type":"ListItem","position":2,"name":"Lobsters","item":"https://daily.dev/sources/lobsters"},{"@type":"ListItem","position":3,"name":"daniel.haxx.se"}]}
```

