Thread: Computers Truecrypt may be compromised
View Single Post
Old 05-29-2014, 07:17 AM   #11
planetdoc planetdoc is offline
Veteran
 

Join Date: Apr 2012
Casino cash: $9995865
Quote:
Originally Posted by htismaqe View Post
So I ask again, why does it matter if Sourceforge has been compromised?
1. It can allow a 3rd party to take over a project and push out malicious code.

2. Although software that they host is open source, most people do not check MD5 checksum's of the software that they download, few check that the available executable matches one compiled independently, and few have the capability to audit the millions of lines of code of each version.

Thus, when the chain of trust is potentially broken (such as when SourceForge has been compromised), than any software hosted from the site becomes potentially suspect and should be viewed with suspicion.

Last edited by planetdoc; 05-29-2014 at 07:43 AM..
Posts: 2,174
planetdoc has disabled reputation
    Reply With Quote