← Back to context

Comment by system2

2 years ago

Honestly, if they provided 100mb source code, would you read it and then compile it? Source code alone doesn't make it secure.

Something like this doesn't require 100 MB of source code. I'd expect a few thousand LoC at most.

And I absolutely do at least a quick visual "sanity check" of the code before compiling and running newly announced software.

  • You can do a sanity check on exe files with VirusTotal and other tools. And if it’s just for testing, you can use a throw-away VM.

Irrelevant. Convenient or probable doesn't matter. What matters is possible vs not possible.

All it takes is one person somewhere who wants to look something over, and they heads-up the rest, and then many others do verify.

And that initial one does exist even though it's not you or me, the same way the author exists, the same way that at least once in a while for some things it is you or me.