4 ms·
i'm always surprised by such comments beside Stallman do people not using anything that contain at least single line of closed/proprietary code really exist?
by dzek69 8y ago
i'm always surprised by such comments
beside Stallman do people not using anything that contain at least single line of closed/proprietary code really exist?
not every closed source stuff is evil, really
- danellis 8y ago> not using anything that contain at least single line of closed/proprietary code It's not just that. The existence of source code doesn't mean the binaries are uninfected. You'd have to actually build it yourself from source. And even then, unless you've audited the source, you're still not sure. Of course, you'd have to build that compiler from source (that you've audited) using...? And all that on an OS with libc, libdl etc that you've built yourself.
- mont 8y agoDon't forget you have to audit the microcode running you're cpu too, and the gate networks executing the microcode, and...
- binaryblitz 8y agoYou joke, but wouldn't we have caught SPECTRE or Meltdown a lot faster if someone had?
- sjcoles 8y agoWhile there is a level where it becomes a masturbatory exercise I think caution is well advised with messaging applications in particular. Sure Slack/Discord are black boxes, but developed by companies that have time and capital invested in proving they are not doing malicious things.
- bassman9000 8y agoIt's better to act as it is, than lament later.
- seba_dos1 8y agoI do sometimes make exceptions, but definitely not for such crucial applications as main communicator. Plus there are other practical reasons to try to limit yourself to FLOSS than fear of hidden malware.
- sgeisler 8y ago> not every closed source stuff is evil, really But how do you know that this closed source software isn't evil? You can't distinguish without an audit by a competent person you trust. Most closed source software isn't audited to a level that I'd deem sufficient for my security. The problem is even worse: proprietary software has a single owner that can be coerced into including (even targeted) backdoors by state level attackers. If I really want to run proprietary software I typically try to containerize it or even run it in VMs.