top | item 46045577

(no title)

kchr | 3 months ago

One of the points made in that paper is that you can't even trust the compiler, even if you write the code yourself. I think this is one of the stronger points as it shows you it is unfeasible to require everybody to audit all source code before running it. Be pragmatic, know your threat model, decide who you trust and move on with more important things in your life.

Full disclosure: am free software advocate.

discuss

order

user3939382|3 months ago

There’s a way to fix Ken’s problem with zero trust. I’ll release it soon.