Damus
Marcos Dione · 1d
nostr:nprofile1qy2hwumn8ghj7un9d3shjtnyd968gmewwp6kyqpqtva8g98fx0fks0pt38vr75tv02t30qd5ev7n5v7fcpl6t44hf7kqzp8d0p nostr:nprofile1qy2hwumn8ghj7un9d3shjtnyd968gmewwp6kyqpq5u6lv635a90tgj2w0ywy44xv3pqj267...
GrapheneOS profile picture
@nprofile1q... @nprofile1q... @nprofile1q... Neither open source or distribution packaging inherently provide privacy or security. It's not the case that people only use software from official repositories regardless.

Contrary to the common misconception, only using software from distribution repositories doesn't avoid trusting the upstream developers and doesn't address supply chain attacks. As an example, Debian shipped a backdoor in sshd after it was included in the xz project as part of the published sources.
1
Marcos Dione · 1d
nostr:nprofile1qy2hwumn8ghj7un9d3shjtnyd968gmewwp6kyqpqtva8g98fx0fks0pt38vr75tv02t30qd5ev7n5v7fcpl6t44hf7kqzp8d0p nostr:nprofile1qy2hwumn8ghj7un9d3shjtnyd968gmewwp6kyqpq5u6lv635a90tgj2w0ywy44xv3pqj267p348nu0v0445y5gw0t7js9u8vnj nostr:nprofile1qy2hwumn8ghj7un9d3shjtnyd968gmewwp6kyqpq98t8kgwqas59rvmng...