|
|
|
|
|
by pciexpgpu
1020 days ago
|
|
I wonder how legit are some of the most popular download sites: e.g ffmpeg windows binaries [1] are hosted from some random person’s site. Sure you can check the checksum etc but that still doesn’t guarantee any relationship with a specific git commit. I would just assume that non-gh or official hosted downloads (where reproducible/attested builds are available) are just state actors by default. Am I paranoid? How do Linux/Mac package managers solve this? [1] https://ffmpeg.org/download.html |
|
https://www.trendmicro.com/vinfo/fr/security/news/cybercrime....