Gentoo Archives: gentoo-amd64

From: Mark Knecht <markknecht@×××××.com>
To: Gentoo AMD64 <gentoo-amd64@l.g.o>
Subject: Re: [gentoo-amd64] Re: "For What It's Worth" (or How do I know my Gentoo source code hasn't been messed with?)
Date: Tue, 05 Aug 2014 18:50:19
Message-Id: CAK2H+ec8A2qHC9wh=D6_AN3cogHSuR56VraCbdftBsA-nD6isw@mail.gmail.com
In Reply to: [gentoo-amd64] Re: "For What It's Worth" (or How do I know my Gentoo source code hasn't been messed with?) by Duncan <1i5t5.duncan@cox.net>
1 On Mon, Aug 4, 2014 at 10:52 PM, Duncan <1i5t5.duncan@×××.net> wrote:
2 >
3 > Mark Knecht posted on Mon, 04 Aug 2014 15:04:12 -0700 as excerpted:
4 >
5 > > As the line in that favorite song goes "Paranoia strikes deep"...
6 >
7 > FWIW,
8
9 I __LOVE__ the idea that my favorite old song has ended up being
10 a contraction everyone uses...
11
12 > while my lists sig is the proprietary-master quote from Richard
13 > Stallman below, since the (anti-)patriot bill was passed in the reaction
14 > to 9-11, my private email sig is a famous quote from Benjamin Franklin:
15 >
16 > "They that can give up essential liberty to obtain a little
17 > temporary safety, deserve neither liberty nor safety."
18 >
19 > So "I'm with ya..."
20
21 Good to know. (Not that I didn't already!)
22
23 <SNIP>
24 > These are good questions to ask, and to have some idea of the answers to,
25 > as well.
26 >
27 > Big picture, at some level, you pretty much have to accept that you
28 > /don't/ know.
29
30 OK.
31
32 <SNIP>
33 > I never kept the link, but it seems the title actually stuck in memory
34 > well enough for me to google it: "Reflections on Trusting Trust"
35 > =:^) Here's the google link:
36 >
37 > https://www.google.com/search?q=%22reflections+on+trusting+trust%22
38 >
39
40 This is a great paper and the Moral section is dead on right. The line:
41
42 "No amount of source-level verification or scrutiny will protect you
43 from using untrusted code."
44
45 is spot on and just about impossible for folks like me. (And I'm _way_
46 beyond the average computer use, as is anyone reading this list.)
47
48 I'll respond/etc. to other parts of your post later but want to
49 give a quick thanks right now.
50
51 Cheers,
52 Mark