---
title: "daniel.haxx.se"
url: https://daily.dev/posts/daniel-haxx-se-besdttbr0
source_url: https://daniel.haxx.se/blog/2024/04/10/verified-curl/
type: article
source: "Lobsters"
published: 2024-04-10T15:21:17.729Z
updated: 2024-05-09T08:43:33.910Z
tags: ["security", "cyber", "curl"]
reading_time: 6
upvotes: 2
comments: 0
language: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# daniel.haxx.se

**[Lobsters](https://daily.dev/sources/lobsters)** · 6 min read · 2 upvotes · 0 comments

## Summary

This post discusses how to verify the integrity of the curl package, including checking for backdoors, binary blobs, and hidden payloads in tarballs. It also highlights the importance of signed tarballs and commits, as well as the acceptance of contributions from anonymous and pseudonymous contributors. The post concludes by emphasizing the need to focus on finding security vulnerabilities in curl rather than attempting to plant backdoors.

## Full article

daily.dev links to this article rather than hosting it. Read it at the original source: <https://daniel.haxx.se/blog/2024/04/10/verified-curl/>

## Similar posts on daily.dev

- [Don’t just attend KubeCon \+ CloudNativeCon, Merge Forward your experience\!](https://daily.dev/posts/don-t-just-attend-kubecon-cloudnativecon-merge-forward-your-experience--l0rpp73x8) · CNCF · 0 upvotes · 0 comments
- [Announcing H2 2026 KCDs](https://daily.dev/posts/announcing-h2-2026-kcds-m96goajm1) · CNCF · 1 upvotes · 0 comments
- [Two months of Open Community Groups](https://daily.dev/posts/two-months-of-open-community-groups-asf52zhbs) · CNCF · 0 upvotes · 0 comments

---

Tags: [#security](https://daily.dev/tags/security), [#cyber](https://daily.dev/tags/cyber), [#curl](https://daily.dev/tags/curl)

[View this post on daily.dev](https://daily.dev/posts/daniel-haxx-se-besdttbr0)
