Comment by xeromal
20 days ago
Yup, the only way to combat this as a smalltime dev would be to turn off auto updates and make people build from source.
20 days ago
Yup, the only way to combat this as a smalltime dev would be to turn off auto updates and make people build from source.
Why woul building from source be safer? Are you veting every single line of third-party source code you compile and use?
You're sure not vetting any byte of an executable, so building from source is safer.
Binaries or source, it's pretty much the same unless you thoroughly vet the entire source code. Malicious code isn't advertised and commented and found by looking at a couple of functions. It's carefully hidden and obfuscated.
1 reply →
yea `curl <url> | gcc` is much safer...
Security through ..rarity? Maybe not for nation state actors though.