Post #2691591
2025-12-05 19:41 UTC
@econads@mendeddrum.org @globcoco@mamot.fr @plumeros@swiss.social @Uddelhexe@mastodon.online The vast majority of open source projects get little to no external review. Nearly none receive in-depth privacy or security review. In general, people trust open source projects because source code is available and someone could audit the sources rather than because anyone is doing it.
The claim that only sources can be reviewed is incorrect and resembles dubious claims that open source is less secure due to attackers being able to find bugs more easily.
Replies (1)
-
@GrapheneOS@grapheneos.social 2025-12-05 19:46
@econads@mendeddrum.org @globcoco@mamot.fr @plumeros@swiss.social @Uddelhexe@mastodon.online Claiming that compiled code is infeasible or substantially harder to review to find vulnerabilities is effectively an endorsement of security through obscurity. You're implying attackers can find vulnerabilities in open source software much more easily. Most open source software does not receive external privacy or security review so it'd be an asymmetric advantage for attackers. Closed source software is NOT the black box you believe it is though.