4 ms·
I agree, though I prefer the word trust; I think in the end most security arguments basically move trust around between entities, so I would either trust the op
by grumdan 8y ago
I agree, though I prefer the word trust; I think in the end most security arguments basically move trust around between entities, so I would either trust the open-source community or Apple.
In this case I decided trust the open-source community more than Apple, since the incentives of people inspecting open-source code probably align better with my own interests than the incentives of Apple.
- dmitriid 8y ago> the incentives of people inspecting open-source code probably align better with my own interests than the incentives of Apple. The incentives of any people are: earn enough money for a peaceful existence. When Heartbleed happened, it turned out that only a handful of people in the entire world have the expertise to do a full audit of the OpenSSL code. And their work is ridiculously expensive. And the audit didn't happen until someone paid for it [1] (I'm not entirely sure it ever completed [2]). People may actually have less incentives to inspect open-source code because there's always the question of life, money, time, work-life balance etc. etc. [1] https://www.zdnet.com/article/ncc-group-to-audit-openssl-for-security-holes/ https://www.zdnet.com/article/ncc-group-to-audit-openssl-for... [2] http://isopensslauditedyet.com http://isopensslauditedyet.com