Re: "For What It's Worth" (or How do I know my Gentoo source code hasn't been messed with?)
Lie Ryan <[email protected]>
| Newsgroups | gmane.linux.gentoo.amd64 |
|---|---|
| Message-ID | <CAGf7mVU1HNkPhMvGE6aAKUSCkiwKMDsZQPhtGZe2-prsTKJg9Q@mail.gmail.com> |
With you having to compile thousands of stuffs if you build from stage 1, I doubt that you will be able to verify every single thing you compile and detect if something is actually doing sneaky stuff AND still have the time to enjoy your system. Also, even if you build from stage 1 and manage to verify all the source code, you still need to download a precompiled compiler which could possibly inject the malicious code into the programs it compiles, and which can also inject itself if you try to compile another compiler from source. If there is a single software that is worth a gold mine to inject with malware to gain illicit access to all Linux system, then it would be gcc. Once you infect a compiler, you're invincible. Also, did you apply the same level of scrutiny to your hardware? For the truly paranoid, I recommend unplugging.