4 ms·
You build binaries and make sure SHA1 matches. Obviously malicious vendor can have custom compiler that inserts backdoor code during compilation and obfuscated
by smm2000 9y ago
You build binaries and make sure SHA1 matches. Obviously malicious vendor can have custom compiler that inserts backdoor code during compilation and obfuscated stuff like that but it dramatically increases complexity and number of engineers who have to know about backdoor. Realistically most companies are not CIA and are not set up for this kind of ops. Essentially it makes it much more risky for company to insert backdoor and gives more incentives for pushing against NSA/etc.