Hacker News new | ask | show | jobs
by CiPHPerCoder 3769 days ago
> But, at some point there must be trust.

Do you trust the developers? Okay.

Do you trust the developers, their infrastructure, AND the supply chain? Maybe a bitter pill to swallow.

Recommended reading: https://defuse.ca/triangle-of-secure-code-delivery.htm