- Nov 30, 2004
- 60,007
- 10,500
- 126
An argument in another thread regarding Chinese software got me thinking about open source software. What would stop somebody from releasing clean source code, but a contaminated binary for mass consumption? I'm assuming it isn't possible to turn a binary into source, so how can it be checked without recompiling, and comparing md5s, or something like that? Is that a legitimate security concern, or is there a reasonable way of quickly checking?
This is probably more applicable to the Linux forum, but Windows software can be had from source too, though it's less common.
This is probably more applicable to the Linux forum, but Windows software can be had from source too, though it's less common.