|
|
|
|
|
by LinuxBender
531 days ago
|
|
Running untrusted code is the weakest link. I agree with this however that would limit just about all software unless it has been properly and deeply inspected by people paid to do just this. If I go through the project pages of all the software that comes with Linux I know I will not find code reviews at each artifact release version that has been reviewed by the NCC group, Google project zero, etc... FWIW it could be said that most of the software in use today is untrusted in that regard, even the most commonly used browsers. Some may think browsers have so many eyes on them that a subtle weakness could not be introduced but I also disagree with that. A more widely used application is an even bigger juicy delicious target for nation state actors to get employed and introduce multiple subtle changes that work in conjunction with one another and OS design flaws. I would wager that every browser has malicious actors either contributing subtle weaknesses or possibly sleeping until they are given orders. |
|