• AwesomeLowlander@sh.itjust.works
    link
    fedilink
    English
    arrow-up
    0
    ·
    3 days ago

    Are you at all aware of the actual details of this incident?

    Tesseract is open source, no?

    It was an intentionally obfuscated line of code that pulled a file direct from his server. A file that was intentionally not in the repo so they nobody would know about it. In IT, we call that malware.

    • misk@piefed.social
      link
      fedilink
      English
      arrow-up
      0
      ·
      3 days ago

      How else could such list work? New Tesseract release for every update to the filter? It wasn’t encrypted.

      • AwesomeLowlander@sh.itjust.works
        link
        fedilink
        English
        arrow-up
        0
        ·
        3 days ago

        To begin with: Apps using such lists make it very clear upfront what they are doing. NOBODY OBFUSCATES THE VERY EXISTENCE OF THE LIST.

        The list can also easily be a part of the repo that’s pulled at runtime. Or viewable and modifiable from within the app itself.

        It wasn’t encrypted.

        It’s a client side app, by definition there’s no easy way to encrypt it. Dude certainly gave it a shot by base-64 encoding it. There was no technical reason to encode a text file.

        • misk@piefed.social
          link
          fedilink
          English
          arrow-up
          0
          ·
          2 days ago

          It was disclosed through user agreement and docs for admins hosting Tesseract. List wasn’t encrypted. We’re going in circles now.

          People are allowed to have political opinions and they’re allowed to express them through software. Don’t like it? Don’t use it.