Comment on Bonfire & Guix, a love story -- fishinthecalculator

<- View Parent
jim3692@discuss.online ⁨1⁩ ⁨week⁩ ago

It’s the first time I see the concept of bootstrappability in the context of security.

Is it really worth the effort?

There are multiple ways to run a supply chain attack. With bootstrappability, one can be sure that the compiler is trusted, but what about the code that the compiler compiles? There was this recent attack to XZ utils, which shows that more attention is needed on the code being merged and compiled.

I think that this just creates a false sense of security.

Contrary to that, I had read about a BSD team (I think FreeBSD) that reviews all the code before each release. This way they have achieved ~5 RCE exploits throughout their entire history.

source
Sort:hotnewtop