HomeSecurityMoq: Criticized for silent data collection

Moq: Criticized for silent data collection

Moq: Criticized for silent data collection

The open source project Moq (pronounced “Mock”) has drawn heavy criticism for quietly including a controversial dependency in its latest release.

See also: Microsoft Patch Tuesday August: Warns of 2 zero-days

Distributed on the NuGet software registry, Moq sees over 100,000 downloads on any given day and has been downloaded over 476 million times during its lifetime.

This week's Moq version 4.20.0 quietly included another project, SponsorLink, which caused an uproar among open source software consumers, who likened the move to a breach of trust.

Ostensibly an open source project, SponsorLink is actually available on NuGet as closed source and contains covert DLLs that collect hashes of users' email addresses and send them to SponsorLink's CDN, raising privacy concerns.

Moq shakes user trust

Last week, Daniel Cazzulino (kzu), one of Moq’s owners and maintainer of the SponsorLink project, added SponsorLink to Moq versions 4.20.0 and above. The move sparked controversy for two reasons: Cazzulino didn’t inform the user base before including the dependency, and the SponsorLink DLLs contain obscure code, making them difficult to reverse engineer and not exactly “open source.” Georg Dangl, a software developer based in Germany, reported that SponsorLink is included in Moq version 4.20.0 and is a closed-source project that scans local data and sends the current developer’s hashed email to a cloud service. The scanning feature is part of the .NET that runs during the build process and is difficult to disable. Dangl warns that this is “quite scary from a privacy perspective.” SponsorLink describes itself as a means of integrating GitHub sponsors into libraries so that users can appropriately link to their sponsorship to unlock features or receive recognition for supporting a project.

GitHub user Mike (d0pare) unzipped the DLLs and shared a rough reconstruction of the source code. The library, according to the analyst, “spawns an external git process to get your email.”

It then calculates a SHA-256 hash of the email addresses and sends it to SponsorLink's CDN: hxxps://cdn.devlooped[.]com/sponsorlink.

Telemetry code hidden inside Moq and SponsorLink (GitHub)
Telemetry code hidden inside Moq and SponsorLink (GitHub)

"Honestly, Microsoft should blacklist this package that works with NuGet providers," writes Austin-based developer Travis Taylor.

"The author cannot be trusted. This was an incredibly stupid move that just created a ton of work for a lot of people.".

Proposal: Israeli hospital hit by ransomware attack

The developer defends the change

In a comment, Cazzulino explained the reasons for adding SponsorLink to Moq versions 4.20.0 and above. He admitted that version “4.20” was “a tweak to make it less serious” and that he had been “testing the waters with SponsorLink for a while.” Cazzulino updated the SponsorLink project README with a “Privacy Considerations” section that clarifies that no real email addresses are collected, only their hashes. The update came after the backlash.

Ankita Lamba, a senior security researcher at Sonatype, told BleepingComputer that the announcement appears to be a reactive response to online backlash, rather than the project being honest about what data is being collected. In the past, Cazzulino has defended his decision to keep SponsorLink closed-source and hidden to prevent some of its controls from being bypassed.

Possible privacy concern

The silent inclusion of SponsorLink in projects, such as moq, is a privacy issue from an ethical and legal perspective.

Moq: Criticized for silent data collection

The inclusion of an obscure closed-source dependency (SponsorLink) in popular open source projects like GitInfo, which was also created by Daniel Cazzulino (kzu) and has been downloaded millions of times, has raised concerns. The collection of email address hashes may not be completely anonymous, as the SponsorLink developer could theoretically compare the collected hashes to a database of leaked email addresses to identify users.

Michał Rosenbaum states that even hashed emails should only be sent after consent. Several developers have threatened to discontinue use of Moq in favor of alternatives or to create tools that would detect and block any projects that run SponsorLink. Some have even suggested boycotting projects that use SponsorLink or reporting it as malware in the NuGet registry.

Read also: Interpol takes down 16shop phishing-as-a-service platform

source of information:bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS