3 ms·
At the end of the day we have to have trust in others especially in opensource. Everything you incorporate in your apps/sites could be malicious.
by spdy 11y ago
At the end of the day we have to have trust in others especially in opensource.
Everything you incorporate in your apps/sites could be malicious.
- andreasvc 11y agoWhy especially in open source? The leap of faith is larger with a binary blob. (Although I admit it doesn't make much difference in practice, most people don't audit source code).
- hguant 11y agoI think the argument is that open source is based on the fundamental ideal of trust - I put this software out into the world so that people can better it, tweak it, make it their own. If those people don't trust you, and have to audit everything they install, the model breaks. Re binary blobs - honestly, for me at least, if I'm installing a blob it's probably because I purchased the software. Maybe it's naive but I more or less assume no company is going to actively screw over a paying customer
- andreasvc 11y agoProprietary software is equally if not more based on trust. Trust without being able to verify.
- jjuhl 11y agoWhich is why you should trust nothing and verify everything.