How can users confidently verify that a FOSS application is running from its published source code? Is there a easy way to check this, or is this based of checksum and hashes?
How can users confidently verify that a FOSS application is running from its published source code? Is there a easy way to check this, or is this based of checksum and hashes?
Related: Ken Thompson: Reflections on Trusting Trust (1984), this SO answer has a decent summary of the article.