Lobsters
Read post

daniel.haxx.se

This post discusses how to verify the integrity of the curl package, including checking for backdoors, binary blobs, and hidden payloads in tarballs. It also highlights the importance of signed tarballs and commits, as well as the acceptance of contributions from anonymous and pseudonymous contributors. The post concludes by emphasizing the need to focus on finding security vulnerabilities in curl rather than attempting to plant backdoors.

    #security#cyber#curl
Apr 10, 2024•6m read time•From daniel.haxx.se
Post cover image
Table of contents
No inexplicable binary blobsNo disabled fuzzersNo hidden payloads in tarballsReproducible tarballsSigned tarballsSigned commitsIs the content in git benign?Anonymous contributorsAnonymous maintainersCan curl be targeted?VulnerabilitiesCredits
Lobsters's image
Lobsters

Lobsters is a community-driven platform for sharing and discussing links to articles, tutorials, and...

1.9K Followers

•

36.1K Upvotes

Would you recommend this post?

Copy link
WhatsApp
Facebook
X
New Squad
  • © 2026 Daily Dev Ltd.
  • Guidelines
  • Explore
  • Tags
  • Sources
  • Squads
  • Leaderboard