General statistics
List of Youtube channels
Youtube commenter search
Distinguished comments
About
HalfSourLizard
Low Level
comments
Comments by "HalfSourLizard" (@halfsourlizard9319) on "revealing the features of the XZ backdoor" video.
There's some confusing language in the video about this: The data would be signed (not encrypted) with the private key and then verified (not decrypted) with the public key.
2
Yeah, I don't understand this 'argument' ... You have absolutely no way to verify anything about closed code other than nebulous claims made by whoever released the software ... and blackbox testing. It's not like code review is any different for closed-source code than for open -- a trusted contributor who violates that trust could just as well have sneaked this backdoor into a closed project ... and it would be nearly impossible to detect beyond seeing some sus network traffic.
1