Gothenburg 2026 - Day 1 - Bad builds

Greg’s work: uses stabilizer (these stabilizers guarantee removing non-malicious differences)

Signal APK: some part was ignored.

sbuild does network isolation for rebuilding

GitHub Runner differences were due to build cache

unintentional bad

intentional bad

diffoscope feature request:

enumerate possible places of shipping bad stuff not present in the source code

  1. small changes in logic in the binary
  2. new functionality in the binary
  3. installation hooks
  4. additional files (e.g. in PATH)
  5. metadata of the path (e.g. new dependency)

Case in F-Droid, Nextcloud News, someone put a package in a Maven repository with a same namespace as the app was using. F-Droid builds from a clean machine, pulling the malicious dependency. The developer has a cache so they weren’t affected. Potentially a targeted attack. This wasn’t detected.