Hacker News new | ask | show | jobs
by qarl2 3 hours ago
> Why would I?

Because then you can install it without depending on a package manager?

1 comments

Yeah, from source in that case. Or using a verified binary if I absolutely had to.
Yes, if you want to, you can do that.

Understand that 99% are comfortable trusting downloads. They know that it's just as easy to sneak backdoors into source code as it is to sneak backdoors into executables.

See also: XZ hack.