Hacker News new | ask | show | jobs
by gertop 66 days ago
It's entirely possible to ship malware in source form... Just look at the numerous supply chain attacks. Nix is a cute project but entirely irrelevant here.
1 comments

It is possible but visible, and it means burning an identity, so it's not irrelevant
Burning an identity? Instead of hacking the server that serves the binary, you have to hack the developer's machine and commit a malicious source change.

I wouldn't consider either of them to burn an identity.