• ulterno@programming.dev
    link
    fedilink
    English
    arrow-up
    7
    ·
    10 hours ago

    The incident from xz gives a good example of where self-compiling stuff would be a good idea.
    The code was mostly fine, but the maintainer managed to include malicious instructions in the binary. Most people who read the source, didn’t realise the possibility. I checked it out afterwards and it was still hard to get.