this post was submitted on 04 Sep 2026
-18 points (12.5% liked)
Rust
8265 readers
30 users here now
Welcome to the Rust community! This is a place to discuss about the Rust programming language.
Wormhole
Credits
- The icon is a modified version of the official rust logo (changing the colors to a gradient and black background)
founded 3 years ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
view the rest of the comments
I use official links and check versions.
Sure, you might today, but tomorrow? How can anyone trust that you wont start serving malicious links?
It's open source. Anyone can audit it. You can create your own sources.list, but if you distribute it, you must open the code. Also, "wid info <package_name>" shows the exact URL it downloads from. Example: wid info llvm shows the official GitHub release link.
Thats how it works in theory, but in practice it comes down to trust more than anything else.
Its more effort to read and validate your list than it is to just go and download the installer directly. So you need people to trust you.
You're absolutely right. Trust is the real challenge, and I'm just starting to earn it. That's why I keep everything open and plan to add checksum verification. I know it takes time. I'm in it for the long run.