• simone@lemmy.org
      link
      fedilink
      English
      arrow-up
      10
      ·
      3 days ago

      Open source software you don’t code review and build yourself can also contain spyware.

      • TerHu@lemmy.dbzer0.com
        link
        fedilink
        English
        arrow-up
        10
        ·
        edit-2
        3 days ago

        while it can, there probably is some arch user who runs the program too and notices it suddenly takes 2ms longer to do something thusly finding the xz attack.

        so, yeah foss isn’t inherently safe, but most probably saf er

        • simone@lemmy.org
          link
          fedilink
          English
          arrow-up
          1
          ·
          3 days ago

          Projects that have lots of attention and assuming you always compile from source. But someone could easily distribute a binary that is different than the source.

          People should do frequent audits, especially network traffic. I had this one file manager that was kinda like Midnight Commander. Someone on a forum said “check out me app” etc. immediately on launch it made network requests…… why? Anyway, definitely don’t use that for long!!