by Xilman (Hermit)
"I would be very suspicious of any binary I was asked to run, unless I compiled it myself."

Really? I guess you must be running Gentoo then, and even then bootstrapped your own compiler from hand-written assembler in order to get the initial gcc working from code you trust.

There are times when you just have to trust a binary whether you like it or not. Reflections on Trusting Trust has a valuable take on the issue.


by zentara (Archbishop) on Oct 22, 2010 at 13:58 UTC
    I agree, but there are certain tradeoffs in trust. I do keep a watch over the software than comes in precompiled form.

    I make a distinction in trust levels.

    I would be more likely to trust a binary that comes from a prebuilt distribution, like Ubuntu; than from some perl hacker who claims he/she dosn't want me to see what the script does. There is just an obvious difference there in threat level.

    At least the distributions make their source packages available. Will the perl hacker make his uncompiled source script available to me?

