5 ms·
Why are so people so fast to trust a new compiler? Have you audited that compiler's source and building the compiler from it with a known good compiler? Are yo
by 3am 12y ago
Why are so people so fast to trust a new compiler?
Have you audited that compiler's source and building the compiler from it with a known good compiler? Are you inspecting the resulting .pyc, and in this case, the resulting PEs? It's a super easy way to inject a compromise into a package that will probably get widely distributed.
full disclosure: link is down for me, so haven't read the article. Been a comment that has been building up for a while for me, and not specific to Nuitka. Same goes for new frameworks/languages/etc.
- coldtea 12y ago>Have you audited that compiler's source and building the compiler from it with a known good compiler? Are you inspecting the resulting .pyc, and in this case, the resulting PEs? It's a super easy way to inject a compromise into a package that will probably get widely distributed. Because nobody is that paranoid?
- hughes 12y agoAnd if they are, they probably aren't in the business of distributing precompiled binaries.
- andreasvc 12y agoWhy limit yourself to new compilers? Every new version of an old compiler could be suspect, every line of code in general. There's no point in being this paranoid, nobody has time for all the audits that might be theoretically desirable. Almost everything you do on a computer relies on trusting an untold number of components.
- waxjar 12y agoI think it unlikely someone would design something complicated like a new compiler / programming language, open source it and attach their real name to the project just to hide an exploit in it. There's much lower hanging fruit.