Gothenburg 2026 - Day 1 - Bad builds
Greg’s work: uses stabilizer (these stabilizers guarantee removing non-malicious differences)
Signal APK: some part was ignored.
sbuild does network isolation for rebuilding
GitHub Runner differences were due to build cache
unintentional bad
- usually harmless
- detecting causes
- this is 90%
intentional bad
- malware/exploits
- detecting would be good publicity
diffoscope feature request:
- show files only present once
- –new-file
enumerate possible places of shipping bad stuff not present in the source code
- small changes in logic in the binary
- new functionality in the binary
- installation hooks
- additional files (e.g. in PATH)
- metadata of the path (e.g. new dependency)
Case in F-Droid, Nextcloud News, someone put a package in a Maven repository with a same namespace as the app was using. F-Droid builds from a clean machine, pulling the malicious dependency. The developer has a cache so they weren’t affected. Potentially a targeted attack. This wasn’t detected.