• 0 Posts
  • 15 Comments
Joined 1 year ago
cake
Cake day: June 12th, 2023

help-circle




  • Womble@lemmy.worldtoOpen Source@lemmy.mlDon't be that guy.
    link
    fedilink
    English
    arrow-up
    6
    arrow-down
    4
    ·
    6 months ago

    You’re right to an extent, but there is nuance. No end user goes through the Debian repositories and checking the source code for each package by hand. You would be well within your rights to be annoyed if a rm -rf / got added into a script in the repos somehow. A level of trust somewhere is unavoidable for things to work smoothly.

    Of course the difference in level of responsibility between core repos and random code pulled of github is vast.


  • But equally equally, if they set up their own communities in public but just an obscure location, they shouldn’t complain that their public posts are public. Security by obscurity is no security. Frankly its the worst of all worlds to have a place like that as it encourages feeling safe while having the possibility of having the rug pulled out from under you at any moment.