Post #2691590
2025-12-05 19:37 UTC
@econads@mendeddrum.org @globcoco@mamot.fr @plumeros@swiss.social @Uddelhexe@mastodon.online
> it's the absolute basic of security, not a guarantee. It's the auditability. If something is closed source you can't check whatever claims it wants to make.
Having access to the source code does not provide the ability to avoid trusting the developers in practice. If it did, widely used projects like the Linux kernel would not have a massive stream of severe vulnerabilities being found which have been present for years and even decades in plain sight.
Replies (1)
-
@GrapheneOS@grapheneos.social 2025-12-05 19:41
@econads@mendeddrum.org @globcoco@mamot.fr @plumeros@swiss.social @Uddelhexe@mastodon.online The vast majority of open source projects get little to no external review. Nearly none receive in-depth privacy or security review. In general, people trust open source projects because source code is available and someone could audit the sources rather than because anyone is doing it. The claim that only sources can be reviewed is incorrect and resembles dubious claims that open source is less secure due to attackers being able to find bugs more easily.