←back to thread

285 points wilsonfiifi | 1 comments | | HN request time: 0.209s | source
Show context
mkesper ◴[] No.45760844[source]
The lot of (partially scary) binary blobs is still an unsolved issue: https://github.com/ventoy/Ventoy/issues/3224
replies(5): >>45760882 #>>45760933 #>>45761425 #>>45761632 #>>45761980 #
i4qpLmoptUph3fZ[dead post] ◴[] No.45761425[source]
[flagged]
junon ◴[] No.45761520[source]
The rationale for needing a random driver makes some sense. The statement that they found a random build that was signed by some randy is a horrifying prospect.
replies(1): >>45762457 #
fukka42 ◴[] No.45762457[source]
Someone compared hashes of the sectors of both drivers and they are identical except for the signature.

You don't know what due diligence was done.

replies(1): >>45762732 #
junon ◴[] No.45762732[source]
I don't, no, but why should I trust the maintainer, and why should the maintainer trust Randy from some random site?
replies(2): >>45763211 #>>45763326 #
1. i4qpLmoptUph3fZ ◴[] No.45763326[source]
To sibling comment: I don't understand your line of reasoning. How does using someone's software make you trust them? Don't you need trust to run someone's software first?