4 ms·
I realize that not everything can be made open source, but I personally don't trust closed source security applications.
by middleclick 10y ago
I realize that not everything can be made open source, but I personally don't trust closed source security applications.
- coldtea 10y agoWhat's to trust exactly? It blocks connections to domains/IPs you want it to, and allows others. You can easily verify that it behaves correctly with common network tools. This is not some deep cryptography shit...
- middleclick 10y agoWhat if it doesn't show a specific application making requests? What if it chooses to not do that? How do we know?
- coldtea 10y agoAs I said, "You can easily verify that it behaves correctly with common network tools". Track its behavior from an exit node of your network and see whether it matches your rules. Not really much difference than manually checking some tens of thousands of lines of an open source application, or trusting that the binary you got from the repo corresponds to the source (and of course even hashes can be tampered). Plus, even if it chose "to not show a specific application making requests" you'd still be blocking all others apps, and thus way better off than not having it installed.
- mattcoles 10y agoI don't trust that it's not doing data collection of it's own.
- quiowqiourqwiou 10y agoexactly. how can one be sure that it doesn't use the network for its own nefarious purposes while hiding its own network activity ?
- jslabovitz 10y agoThe app costs $35. I presume this is a workable business for the developer, and therefore little economic incentive for data collection or other backdoor/nefarious tactics. I'm much less trusting of free software like most ad-blockers where I have to wonder how they're really making their money.
- tedmiston 10y agoThey've also been on the Mac for 10+ years.
- leejoramo 10y agoObjective Development were there from the very beginning of Mac OS X. And prior to that, they were a well known developer for NeXT. Their LaunchBar app originated on NeXTSTEP.
- beardog 10y agoIt depends what you mean by "free". Of course all software should be handled with varying degrees of skepticism, but open source software can be directly verified (though this also requires building from source), and you don't have to just hope that the author was honest.
- patrick_haply 10y agoFunnily enough, I vaguely recall that the crack for an older version involved setting a rule where the app would block its own traffic to their own license server. I'm not sure that validating a license counts as data collection, but still pretty funny IMO.