3 ms·
Client software (anything that runs on the user's device) should be open source for two reasons: 1. It's easier to audit, although binary analysis is still use
by CiPHPerCoder 9y ago
Client software (anything that runs on the user's device) should be open source for two reasons:
1. It's easier to audit, although binary analysis is still useful (and reverse engineers are often better at finding security holes than someone doing a source code review).
2. Reproducible builds.
Server software doesn't need to be open source. If you have E2E in your open source software, you don't need to trust the servers at all: https://paragonie.com/blog/2016/03/client-authenticity-is-not-server-s-problem https://paragonie.com/blog/2016/03/client-authenticity-is-no...
- pvg 9y agoThat seems like a very weak "should" and more of a "nice when it happens"
- CiPHPerCoder 9y agoMy previous comment is RFC 2119 compliant.
- pvg 9y agoThat's 90's RFC technology! WOULD BE NICE is an unfortunate omission.