This is slightly paranoid thinking, but considering the long evolution of Smalltalk live images (apparently all the way from the original Xerox PARC ST80 [1] ) in relation to Ken Thompson's "Reflections on Trusting Trust" [2] - are there any mechanisms to prevent trojan code living undetected inside a Smalltalk compiler/decompiler ? Bruce Schneier [3] provides a shorter overview of [2] if that is not to your taste. To what degree might this ever be an issue with Pharo and how might it be mitigated ? cheers, -ben [1] http://lists.squeakfoundation.org/pipermail/squeak-dev/1999-January/011116.h... [2] http://www.ece.cmu.edu/~ganger/712.fall02/papers/p761-thompson.pdf [3] http://www.schneier.com/blog/archives/2006/01/countering_trus.html