Trojan Horse Code
Have source code at hand
(even if impossible to check)
Do not install programs from
dubious origin
To not install patches from dubious
origin
Verify MD5 signatures
Prefer pull over push for obtaining
software