| ▲ | tom_alexander 2 hours ago | |||||||
> untrusted I think the important distinction is _everything_ should be considered untrusted because even trustworthy software can become malicious. For example, the XZ Utils backdoor[0]. On Android, everything I run is subject to the permission model and sandboxed. That is not the case on Linux. | ||||||||
| ▲ | seba_dos1 2 hours ago | parent [-] | |||||||
It's not the case on Android either and it could be subjected to a XZ-like backdoor just as anything else. | ||||||||
| ||||||||