Oddbean new post about | logout
 If the app you use is open source but you didn't build from source, you actually have no idea what code you're running  
 I trust nostr:nprofile1qqsyvrp9u6p0mfur9dfdru3d853tx9mdjuhkphxuxgfwmryja7zsvhqpzamhxue69uhhv6t5daezumn0wd68yvfwvdhk6tcppemhxue69uhkummn9ekx7mp0qyghwumn8ghj7mn0wd68ytnhd9hx2tcewvzaw 🤷🙏 
 even when you build from source you dont always know whats in the code. 😏 
 Just ask xz Utils 
 Don't most open source projects sign their binaries? 
 If you write a program but you have dependencies, you actually have no idea what code you're running. 
 If you write a whole program but didn't make the compiler, you actually have no idea what code you're running.  
 If you weote the compiler but didn't write the cpu microcode, you actually have no idea what code you're running. 
 I built many software from source and have no clue what I was actually running 
 Ain't nobody got time for dat 
 If you want to bake a cake, the first step is to create the universe.

nostr:nevent1qqs95ag0htvasesgaay7pea6nju4cvmf6cttrhnrukll3acwug0smhgpz4mhxue69uhhyetvv9ujuerpd46hxtnfduhsyg8zenmu7gzq8ulj5jj4kv50ph3muwz43f747vmr9ld2alrjdswgavpsgqqqqqqs5fljkc 
 Do hashes of nix builds count?