Hacker News new | ask | show | jobs
by erickt 3188 days ago
Organizer here!

Aidan actually submitted two entries. This particular entry that exploited this unsoundness bug wasn't actually the winner, even though it was great (horrible?). We weren't sure if the underhandedness would survive code review in this particular instance. He had to jump through some hoops [1] to trigger the unsoundness.

His other entry blew us away. It took us a long time to figure out how it worked.

[1]: https://github.com/rust-community/underhanded-submissions/bl...

2 comments

That other entry is probably the most creative exploit of a language package management ecosystem I've ever seen.
Oops, thanks for the correction!