Actual question. Isn't installing stuff from third party repos like super dangerous? The package scripts run with root access, right?
So, I guess you could tell if the hash of the package matches the hash of the code after you build it... But, what about upgrades on that package after it is installed? They could change the setup scripts and screw a lot of people right?
Not saying these guys do it, just wondering about security stuff.
"Science isn't about WHY. It's about WHY NOT. Why is so much of our science dangerous? Why not marry safe science if you love it so much. In fact, why not invent a special safety door that won't hit you on the butt on the way out, because you are fired." — Cave Johnson (Portal 2)
Hard disagree. If you're running something business-critical, the support that you get with a RHEL license {or any other vendor, for that matter) is worth its weight in gold.
If you can't fix something, you don't want to be looking for solutions by sifting through forum posts directed at home users when the business is losing thousands of dollars per hour. That's what the license is for, and that's what you pay for.
Think about it practically. Microsoft is not an advertising company, they make their money from enterprise software. Windows is installed on billions of computers. The infrastructure required to accept and process every single key pressed by every single windows user and turn it into something usable would be enormous. And for what? To make a few extra millions by selling it to some advertising company?