Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

If the RPM/deb comes from a Linux distribution then there is a good chance there is a separate maintainer and the binary package is always built from the source code by the distro.

Also if the upstream developer goes malicious there is a good chance at least one of the distro maintainers will notice and both prevent the bad source code being built for the distro & notify others.



Browser extensions come from the Chrome/Firefox addon store, though and not through distros.


And maybe that's why we have the problem that is being discussed ? No third party that would audit and build extensions from source.


Everybody seems to hate distributions though.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: