37 ms·
But there are no guarantees about the source either unless I am willing to audit all of it?
by pingec 8y ago
But there are no guarantees about the source either unless I am willing to audit all of it?
- deleted 8y ago[deleted]
- mihaifm 8y agoI agree, that's why signed source code releases are the safest thing you can get. Keepass has signed releases (including the source code archive) that can be checked with OpenPGP. https://keepass.info/integrity.html https://keepass.info/integrity.html
- svenfaw 8y agoIf you trust the signed source code there's no reason you shouldn't trust the signed binary - unless you have sufficient time and expertise to audit the source.
- mihaifm 8y agoThis is how I view it: * Being open source protects against a malicious developer. Otherwise there is nothing preventing him to build the binary with a different source, and send the passwords to his own server. * Signed code archive prevents against a compromised hosting site.
- perl4ever 8y agoIn order to get from a trusted source to a trusted binary, you have to trust the compiler and its dependencies as well, I think.