Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

> Usually there is a better way to do it in almost all cases where people feel the need to reach for "eval"

unfortunately thats just standard in configure scripts, for example from python:

``` grep eval Python-3.12.2/configure | wc -l 165 ```

and its 32,958 lines of code, plenty of binary fixtures as well in the tarball to hide stuff.

who knows, but I have feeling us finding the backdoor in this case was more of a happy accident.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: