Hacker News new | past | comments | ask | show | jobs | submit login

Because it's a security tool so trusting a binary upfront defeats the purpose. With source you at least have the option to inspect what it really does.



does the stated purpose of the tool influence whether or not you can trust it?


I think that question is a little backwards.

Certain tools are more likely to be used by people working in spaces where they should/must be less trusting.

If there was a tool (there is) to scan my platform deployment against some NCSC/NSA guidance for platform security, and I wanted to use it, I'm likely operating in a space that should consider being cautious about running random tools I find on the internet.


right, but in that scenario I'd assume you'd also want to take a look at your ostensibly unrelated tools


If you're trying to improve the security of your product by running random binaries from the Internet you're going to have a bad time


That's how most people run compilers


This is argumentum ad absurdum - there is a reason why trusting your kernel and compiler is a reasonable compromise, even though there might be security issues in them, but random pieces of software downloaded from the Internet is not.


Wait ... you download random compilers from the internet? Or are you asserting equivalence between getting go from Google or Xcode from Apple and an random home brew install?


also if you're not trying to improve the security of your product by running random binaries from the internet. I'm concerned at the inability to separate the concepts of "what it does" and "what it says it does".

The idea that whether or not it needs scrutiny is impacted by your goals with the software is... creative


Uh? OP just released a docker image and wants to release a homebrew thingy. Even assuming that was you say is somehow sensible, it's not the reason, no. You're just grasping at straws.




Consider applying for YC's Fall 2025 batch! Applications are open till Aug 4

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: