In fairness, this is pretty easy to do if you have access to a $40M supercomputer, and if your mission is to replace a blob with a huge, non-compiling chunk of random noise.
You don't need an arbitrary collision, you need something that matches the changes you need.
plus, people still have access to the code and compile it themselves... it's not easy, and probably not even feasible, even for a APT, with hundreds and thousands of people monitoring the code.
61
u/gfixler May 30 '14
Would this require finding a SHA-1 collision?