Hacker News new | ask | show | jobs
by jMyles 3769 days ago
Surely you aren't suggesting that a reasonable answer is to read the code yourself and compare it to a known version?

Obviously, the mainstream way is a hash-based file verification.

Which again, everybody needn't do - only a small number - in order to catch a bad actor in the act.

But I presume you are trying to make some bigger point. What is that?

1 comments

It's not reasonable at all. But the only correct answer is reviewing the code yourself.