4 ms·
does the stated purpose of the tool influence whether or not you can trust it?
by menacingly 2y ago
does the stated purpose of the tool influence whether or not you can trust it?
- spoonjim 2y agoIf you're trying to improve the security of your product by running random binaries from the Internet you're going to have a bad time
- saagarjha 2y agoThat's how most people run compilers
- benterix 2y agoThis is argumentum ad absurdum - there is a reason why trusting your kernel and compiler is a reasonable compromise, even though there might be security issues in them, but random pieces of software downloaded from the Internet is not.
- Ensorceled 2y agoWait ... you download random compilers from the internet? Or are you asserting equivalence between getting go from Google or Xcode from Apple and an random home brew install?
- menacingly 2y agoalso if you're not trying to improve the security of your product by running random binaries from the internet. I'm concerned at the inability to separate the concepts of "what it does" and "what it says it does". The idea that whether or not it needs scrutiny is impacted by your goals with the software is... creative
- alias_neo 2y agoI think that question is a little backwards. Certain tools are more likely to be used by people working in spaces where they should/must be less trusting. If there was a tool (there is) to scan my platform deployment against some NCSC/NSA guidance for platform security, and I wanted to use it, I'm likely operating in a space that should consider being cautious about running random tools I find on the internet.
- menacingly 2y agoright, but in that scenario I'd assume you'd also want to take a look at your ostensibly unrelated tools