Earlier quoted context omitted.
I don't really see how anyone can win this challenge (other than how already done). The guy will be super cautious of any pull requests.
You could probably hide it pretty effectively during a normal pull request to fix an existing issue. As long as they aren't greping for the string anyhow. If he's going to use tools to to search a PR for the string, you'd have to obfuscate it. There are plenty of string and / or byte array manipulation techniques to sufficiently hide something like this as long as it's masked by an otherwise real PR.
Did I just win?
61–70 of 140 posts
Re: Did I just win?
#622. Offer a $100 bounty to people who can trick me into getting some string into my projects. The easiest way to "trick" me of course is to hide it inside of a PR which fixes a real issue.
3. Find and remove the string before merging the PR. I've had one of my issues fixed for free. Rinse and repeat!
Bonus Round: Stage an announcement on twitter and have someone cleverly trick me into including the string on my website (which I was totally going to do anyway). Post clever trick to code geek social media and reap the sweet free viral marketing and hackers trying to earn a Benjamin.
Re: Did I just win?
#63Would you pay 100 usd to get on the front page of HN and who knows what other popular sites? Maybe it's just a marketing stunt
Re: Did I just win?
#64Earlier quoted context omitted.
The only way that would work is if he committed copy/pasted code without reviewing it first, which is highly unlikely. Or at least I would hope it is, given that he's actually challenged people to do this.
I don't really see how anyone can win this challenge (other than how already done). The guy will be super cautious of any pull requests.
Re: Did I just win?
#65What exactly happened here? All I see is a highlighted line that seems to have already been there.
A guy issued a challenge saying he'd give $100 to anyone who could trick him into inserting a certain string into any of his software projects. Another guy responded "You should put this challenge on your website." The first guy said "Good idea" and proceeded to do so, thus including the string in one of his software projects: his website. GG
(And kudos to the originator for acknowledging that.)
Re: Did I just win?
#66Re: Did I just win?
#67Would you pay 100 usd to get on the front page of HN and who knows what other popular sites? Maybe it's just a marketing stunt
Disclosure: He and I have been friends for years.
Re: Did I just win?
#68Earlier quoted context omitted.
I think you read his statement backwards :) He's advocating social engineering whenever possible.
Ah, I think my brain got led down a "garden path", a concept I just learned had an official name from yesterday's Parsey McParseface announcement https://en.wikipedia.org/wiki/Garden_path_sentence
Re: Did I just win?
#69It's not clever to hack something that you can socially engineer, and that should be hacking 101. Clever win.
That was the challenge. DefuseSec specifically said he would "give $100 USD to anyone who can trick me into inserting the string".
He clearly intended for some variant of "any of my software projects that other people actually use", but failed to specify that detail.
But it's nonetheless hilarious. Laughs all around.
Re: Did I just win?
#70It's not clever to hack something that you can socially engineer, and that should be hacking 101. Clever win.
That was the challenge. DefuseSec specifically said he would "give $100 USD to anyone who can trick me into inserting the string".
Now insert that string into Linux source code, and I ll get surprised.