Skip site navigation (1)Skip section navigation (2)
Date:      Sun, 18 Mar 2001 10:47:17 -0800
From:      Rich Morin <rdm@cfcl.com>
To:        freebsd-stable@freebsd.org
Subject:   Re: ports vs. packages...
Message-ID:  <p050019b2b6dab14856c1@[192.168.168.205]>
In-Reply-To: <20010318194637.A10260@acc.umu.se>
References:  <3AB3C1C2.67E1AB9B@yahoo.com> <20010317125349.E22316@mollari.cthul.hu> <20010318194637.A10260@acc.umu.se>

next in thread | previous in thread | raw e-mail | index | archive | help
At 7:46 PM +0100 3/18/01, Markus Holmberg wrote:
>Isn't there a small security advantage with building from source
>(compared to downloading packages from an untrusted party)?

Access to the source code (and even a close examination of it) isn't
enough.  See Ken Thompson's Turing Award lecture, "Reflections on
Trusting Trust": http://cm.bell-labs.com/who/ken/trust.html

-r
-- 
http://www.cfcl.com/rdm - home page, resume, etc.
http://www.cfcl.com/Meta/md_fb.html - The FreeBSD Browser
email: rdm@cfcl.com; phone: +1 650-873-7841

To Unsubscribe: send mail to majordomo@FreeBSD.org
with "unsubscribe freebsd-stable" in the body of the message




Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?p050019b2b6dab14856c1>