The really impressive part is that NOBODY realised this in the last 5-6 years.
Login to reply
Replies (2)
Ai.... It can now be a projects worst enemy and best friend.
People 'verify' source code far less than people actually believe. The audience of people who actually can are less than people think too. The entropy code was likely read by many people, many times. It means most did not actually understand what was written. Larger projects pay for AppSec teams to do assurance testing / 'audits' because just having visible source code isn't equal to an audit.
Suspected and known malware get a more documented, deep analysis by security firms compared to most open source projects.