Elektrine lite

← Feed

@GrapheneOS@grapheneos.social

Post #2691576

2025-12-02 20:49 UTC

@plumeros@swiss.social @globcoco@mamot.fr @Uddelhexe@mastodon.online > But OSS can be reviewed by anybody at anytime, the developers cannot control by whom. Your belief that closed source software is a black box which cannot be externally reviewed is incorrect. > But who prevents closed source developers of removing backdoor code just before a review and add it immediately afterwards again? Closed vs. open source doesn't work the way you believe it does. Closed source software means not having sources, not lacking the code.

Replies (3)

  • @plumeros@swiss.social 2025-12-02 20:54

    @GrapheneOS@grapheneos.social @globcoco@mamot.fr @Uddelhexe@mastodon.online > Your belief that closed source software is a black box which cannot be externally reviewed is incorrect. If the manufacturer allows it, it can be reviewed. If not, no way to review the source code. In this case only reverse engineering may help. > Closed vs. open source doesn't work the way you believe it does. Closed source software means not having sources, not lacking the code. I think that's no answer to the question.

    Open ##2691577

  • @plumeros@swiss.social @globcoco@mamot.fr @Uddelhexe@mastodon.online > Who selects the reviewers? It's all in the hands of the closed source manufacturer. No, that's not how it works. Closed source software still has the compiled code available for review, which is often the best format for finding a subtle backdoor which can be inserted as part of the toolchain or through very subtle approaches. Source code is usually the best form of the code to look for accidental vulnerabilities but a backdoor is a much different thing.

    Open ##2691579

  • @econads@mendeddrum.org 2025-12-05 19:22

    @GrapheneOS@grapheneos.social @plumeros@swiss.social @globcoco@mamot.fr @Uddelhexe@mastodon.online and without the sources to compile yourself, how can you be sure they match?

    Open ##2691587