5 ms·
And if you're using Ubuntu, you're trusting package managers, and if you're using Gentoo, you're trusting original developers (how often do you audit source cod
by Myrth 10y ago
And if you're using Ubuntu, you're trusting package managers, and if you're using Gentoo, you're trusting original developers (how often do you audit source code?)
- Sir_Cmpwn 10y ago>And if you're using Ubuntu, you're trusting package managers, and if you're using Gentoo, you're trusting original developers This is correct. Consider, however, the motivations of the people involved. Apple's motivations are to make money from you. Debian's motiviations (intentionally avoiding Ubuntu here) are to make a good user-centric system. Packages are signed by named individuals that I can personally get to know and trust, and with an accessible process - I can download their package sources and build or verify or tweak them the same way that the maintainer can, report bugs and ask questions directly to them, etc. I trust this model much more than I trust the model of a company who, at the end of the day, has a bottom line and will make compromises to ensure it remains where they need it. Apple is very well known for using proprietary formats, adapters, you name it. Apple's cloud is also write-only, they intentionally make it difficult for you to pull data out of it and interop with other services. These decisions serve the company's interests, not yours. >how often do you audit source code? You would be surprised!
- Jerry2 10y agoWho do you think employs vast majority of Linux developers? Who do you think writes they paychecks? Ever looked into who the biggest Red Hat customer is? Hint, it's the DoD.
- aioprisan 10y agoSource?
- elmigranto 10y ago>>how often do you audit source code? >You would be surprised! It doesn't really matter if you do. OpenSSL is one example showing there are critical mistakes of grand level everywhere, same as there might be cleverly hidden backdoor in that multi-100k source tree (or any of the myriad of dependencies) you "audited".
- riboflava 10y agoIt's still a lot better than not having the source. There are tons of other benefits too. The one downside is CPU cost to compile everything yourself.
- thingexplainer 10y ago>> how often do you audit source code? > You would be surprised! How often do you audit OwnCloud's source code? (I'd describe it as "naive.")
- Sir_Cmpwn 10y agoI actually don't use OwnCloud, so never.
- thingexplainer 10y agoSomething to consider when you're comparing products based on "trustworthiness."
- new299 10y agoIt's interesting because at some level, particularly with closed source products trusting the company developing the product is important. Apple have made some effort to stand up for the privacy of their users. Dropbox on the other hand have board members who support and have authorized warrantless wiretaps: http://www.drop-dropbox.com/ http://www.drop-dropbox.com/
- Dylan16807 10y ago> board members Plural? Who else? There's a difference between bringing in a single famous person and the rest of the board agreeing with them on certain issues.
- newman8r 10y agoI personally think their privacy stance was mostly to protect their own interests rather than any concern for the common man, but they were able to spin it really well and get great publicity as usual. It hurts me to say this as an owner of 2 MBPs and a mac pro which I love, but Apple is not on our side and it's painfully obvious.
- kinkdr 10y agoThat's exactly right and what people complain about. That Dropbox betrayed the trust they(users) were giving to them(Dropbox). I don't necessarily agree with them, but that's the sentiment here. Edit: by the way, regarding open source projects, it doesn't matter if you don't look at the code personally. Somebody else does, and if there is problem with it, it becomes a huge public scandal sooner or later.