3 ms·
Yup, the only way to combat this as a smalltime dev would be to turn off auto updates and make people build from source.
by xeromal 8mo ago
Yup, the only way to combat this as a smalltime dev would be to turn off auto updates and make people build from source.
- tjwebbnorfolk 8mo agoyea `curl <url> | gcc` is much safer...
- trympet 8mo agoSecurity through ..rarity? Maybe not for nation state actors though.
- m-schuetz 8mo agoWhy woul building from source be safer? Are you veting every single line of third-party source code you compile and use?
- g-b-r 8mo agoYou're sure not vetting any byte of an executable, so building from source is safer.
- m-schuetz 8mo agoBinaries or source, it's pretty much the same unless you thoroughly vet the entire source code. Malicious code isn't advertised and commented and found by looking at a couple of functions. It's carefully hidden and obfuscated.
- g-b-r 8mo agoThat's However much the code is hidden and obfuscated, some parts of the source code are going to be looked upon. For a binary, none, ever, except in the extremely rare case that someone disassembles and analyzes one version of it. The fact that open-source doesn't coincide with security doesn't mean that it isn't beneficial to security.