Earlier quoted context omitted.
>> "...easy to verify with a disassembler." Have to laugh at this, because only on HN is the use of a disassembler considered "easy." True story, I program computers for a living, and I have literally no idea how to verify anything at all with a disassembler. Or even approximately how one works.
We're talking about a breach of a major distribution. It's the job of someone in charge to do the analysis, not every single end user. To them , it is easy. And I'm talking about looking at a 20 byte function; you could figure it out if you wanted.
[1] I don't use Ubuntu so maybe it doesn't fully apply here. On Arch using pacman, the list of mirrors/caches is mostly commented out so that people can choose their own. They are "trustworthy" essentially until they're not, but we have signature checking to fall back on. In the physical world we don't have this, thus the setup of my (again, flawed) analogy.
Any more involved than that and it's missing the spirit of what I was trying to say, but I admit that the disassembler response made me chuckle.