Re: "For What It's Worth" (or How do I know my Gentoo source code hasn't been messed with?)

Lie Ryan <[email protected]>
Newsgroups gmane.linux.gentoo.amd64
Message-ID <CAGf7mVU1HNkPhMvGE6aAKUSCkiwKMDsZQPhtGZe2-prsTKJg9Q@mail.gmail.com>
With you having to compile thousands of stuffs if you build from stage 1, I
doubt that you will be able to verify every single thing you compile and
detect if something is actually doing sneaky stuff AND still have the time
to enjoy your system. Also, even if you build from stage 1 and manage to
verify all the source code, you still need to download a precompiled
compiler which could possibly inject the malicious code into the programs
it compiles, and which can also inject itself if you try to compile another
compiler from source. If there is a single software that is worth a gold
mine to inject with malware to gain illicit access to all Linux system,
then it would be gcc. Once you infect a compiler, you're invincible.

Also, did you apply the same level of scrutiny to your hardware?

For the truly paranoid, I recommend unplugging.
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.