▲ | mr_mitm 5 days ago | ||||||||||||||||
Simply running the software means trusting the developer. But even then, do you really read the commits comprising the latest Firefox update? How would I review the updates for my cell phone? I just hit "okay", or simply set up auto updates. | |||||||||||||||||
▲ | skydhash 5 days ago | parent [-] | ||||||||||||||||
I trust Debian, and I do trust Firefox. I also trust Node, NPM, and Yarn. But I don’t trust the myriad packages in some rando projects. So who I trust got installed by apt. Anyone else is relocated to a VM or some kind of sandbox. | |||||||||||||||||
|