Your point is well taken, however I don't think you should just write off such products, after all there is allways the possibility that software is contaminated after writing the code (e.g. the compiler, malware on build system, or the webserver, or on my PC, etc.)
Sometimes it does make sense to check out the smoke to see if there is realy a fire.
A number of big software names have managed to release software that was infected post build, it is unfortunate, but it happens.
|