3 ms·
Building from source doesn't have to be inaccessible, if the build tooling around it is strong. Modern compiled languages like Go (or modern toolchains on legac
by initplus 5y ago
Building from source doesn't have to be inaccessible, if the build tooling around it is strong. Modern compiled languages like Go (or modern toolchains on legacy languages like vcpkg) have a convention of building everything possible from source.
So at least for software libraries building from source is definitely viable. Fro end user applications it's another story though, doubt we will ever be at a point where building your own browser from source makes sense...
- garmaine 5y agoBinary reproducible builds are still pretty inaccessible though.
- bigiain 5y agoBuilding from source also doesn’t buy you very much, if you haven’t inspected/audited the source. The upthread hypothetical of a compromised package manager equally applies to a compromised source repo. _Maybe _ you always check the hashes? _Maybe_ you always get the hashes from a different place to the code? _Maybe_ the hypothetical attacker couldn’t replace both the code you download and the hash you use to check it? (And as Ken pointed out decades ago, maybe the attacker didn’t fuck with your compiler so you had lost before you even started.)