3 ms·
The fact that it is FOSS makes it _easier_ for someone to compile it with a backdoor or trojan. I would say the need for a certificate is _higher_ there. You do
by rgj 6y ago
The fact that it is FOSS makes it _easier_ for someone to compile it with a backdoor or trojan. I would say the need for a certificate is _higher_ there. You don’t need to trust the developers, you need to be able to trust the people who have built the executable.
- gus_massa 6y agoFor example, for some time SourceForge used to offer the executable with their own "installer" https://www.howtogeek.com/218764/warning-don%E2%80%99t-download-software-from-sourceforge-if-you-can-help-it/ https://www.howtogeek.com/218764/warning-don%E2%80%99t-downl...
- dependenttypes 6y agoWell, viruses existed for ages, so I do not think that it really makes it easier. The reason that you do not need a signed executable as much is that people can just compile one themselves.