this post was submitted on 31 Mar 2024
453 points (98.3% liked)

Open Source

31417 readers
16 users here now

All about open source! Feel free to ask questions, and share news, and interesting stuff!

Useful Links

Rules

Related Communities

Community icon from opensource.org, but we are not affiliated with them.

founded 5 years ago
MODERATORS
 

Thought this was a good read exploring some how the "how and why" including several apparent sock puppet accounts that convinced the original dev (Lasse Collin) to hand over the baton.

you are viewing a single comment's thread
view the rest of the comments
[–] [email protected] 22 points 8 months ago* (last edited 8 months ago) (2 children)

Boostrapping a full distribution from a 357-byte seed file is possible in GUIX:

https://lemmy.ml/post/8046326

If that seed is compromised, then the whole software stack just won't build.

It's an answer to the "Trusting Trust" problem outlined by Ken Thompson in 1984.

[–] [email protected] 43 points 8 months ago (1 children)

Reading a bit into this https://guix.gnu.org/manual/en/html_node/Binary-Installation.html The irony!

The only requirement is to have GNU tar and Xz.

[–] [email protected] 7 points 8 months ago

Hahaha! Oh dear

[–] [email protected] 7 points 8 months ago

That's cool. Thank you.