Elektrine lite

← Feed

@GrapheneOS@grapheneos.social

Post #2691580

2025-12-02 20:59 UTC

@plumeros@swiss.social @globcoco@mamot.fr @Uddelhexe@mastodon.online Closed source software is not a black box and the code can be reviewed, contrary to common misconceptions. When you're talking about backdoors which can be inserted as part of compiling it, that's often the form which is needed for reviewing it. Even with reproducible builds + open source, the source code can be written in a way which deliberately masks a vulnerability in subtle ways. You're talking about backdoors where it's deliberately done and hidden.

Replies (3)

  • @plumeros@swiss.social 2025-12-02 21:04

    @GrapheneOS@grapheneos.social @globcoco@mamot.fr @Uddelhexe@mastodon.online > You're talking about backdoors where it's deliberately done and hidden. I meansoftware quality in general and backdoors in particular. > Closed source software still has the compiled code available for review, ... Following this logic OSS wouldn't make any sense then, as users have always the binary code for execution and for review.

    Open ##2691581

  • @plumeros@swiss.social 2025-12-02 21:06

    @GrapheneOS@grapheneos.social @globcoco@mamot.fr @Uddelhexe@mastodon.online > Even with reproducible builds + open source, the source code can be written in a way which deliberately masks a vulnerability in subtle ways. This is what happened Easter 2024 with zx library in ssh.

    Open ##2691583

  • @hyc@mastodon.social 2025-12-06 08:56

    @GrapheneOS@grapheneos.social @plumeros@swiss.social @globcoco@mamot.fr @Uddelhexe@mastodon.online the compiled output of proprietary code is often obfuscated to prevent reverse engineering. E.g. Adobe binaries are intentionally obfuscated. Saying closed source code can still be reviewed drastically misrepresents the difference in difficulty.

    Open ##2691585