3 ms·
Because you would need to write and/or audit your entire technology toolchain — software, build tools, operating systems, hardware, etc — which isn't feasible f
by kingnight 6y ago
Because you would need to write and/or audit your entire technology toolchain — software, build tools, operating systems, hardware, etc — which isn't feasible for anyone.
- the_gipsy 6y agonot a single person, but the sum of all people looking at the different parts. that's how open source works.
- dkonofalski 6y agoSure, but then you're putting your trust in those people. The point was that an individual can't possibly have the time or resources to do it themselves and so, at some point, they have to put their trust in someone else.
- baddox 6y agoAnd thus you would need to trust those people.
- whynotminot 6y agoI've said this before, but the dogmatic belief that open source automatically means something is safer just isn't true. In theory it means something could maybe be safer, but it far from guarantees it.
- gggmaster 6y agoBut for a closed source one there’s definitely no way to audit the source code.
- fiddlerwoaroof 6y agoSure there is: tools like strace, dtrace and eBPF let you “peak under the hood” of nearly any application, not to mention disassemblers like IDA Pro and Ghidra. I have debugged all sorts of issues with closed source applications using these tools.
- Seirdy 6y agoBeing able to inspect the code is a necessary but insufficient measure for being secure. If you cannot inspect the source code, you are not fully aware of how the program works. Tools like strace can help you analyze a program's behavior from the outside, but you get limited insight into its internals (e.g., what algorithms is it using?). Being open source does not automatically make software more secure. A successful compilation doesn't automatically make your code bug-free. Yet both are necessary to achieve the desired goal: security and correctness, respectively.
- whynotminot 6y agoHow often do you inspect the code of the open source programs you use every day? How about when updates come out? Do you check again? Or, do you trust that someone has looked at it? How much faith do you have in someone out there in the community? My point isn't that open source isn't a good thing--my point is that it's not the silver bullet a lot of people blindly assume it to be. Hence the second line of my post: > In theory it means something could maybe be safer, but it far from guarantees it.
- the_gipsy 6y agoneither did I say it's automatically safe, nor define "safe" as in bug free. The commented I replied to implied that one would walk through the entire stack, every line of code, to audit e.g. an app running on a phone. This is most certainly not what OP meant. Rather, on a whole OSS is mostly transparent, while proprietary software is not. There are of course bugs, but that's not the focus here with "safety". What we care about is intention. Private companies's have a track record in implementing features that go directly against the benefit if their end-users, e.g. tracking or vendor-lock-in. These anti-features, like the one described in the article, are much harder to detect precisely because the software is proprietary.
- dogecoinbase 6y agoThe (ongoing) saga of libssh alone should be enough convincing that many eyes do nothing as regards shallowness.
- rimjongun 6y agoI read in a news paper that one time this search party completely missed a young girl they were looking for. Your logic would dictate that search parties are a waste of time. Is open source a panacea? No, clearly, as you stated. Are more eyes, even untrained ones, better than no eyes? Ask all the people saved by search party volunteers every year.
- TheDong 6y agoI mean, I've known a few developers that worked at apple. I trust them every bit as much as the average developer who reads open source code. They vouched that the code they worked with at apple was attempting to be secure and wasn't trying to steal user's data. If I'm not going to read the source code myself either way, why should I trust that random open source code-reader X who says "yup, didn't see any malicious code" vs a developer friend who works for apple and says "yup, no malicious code"? Honestly, more often than not there's a lot of overlap between those people... And I'd bet that there's a ton of eyes I'd trust on iOS's source code given how many devs apple pays to work on it, while I think there's far fewer on most non-corporate open source projects.
- lwhi 6y agoI don't think the issue we should worry about will always just be one bad actor in an organisation. A corporation like Apple (or TikTok) will sometimes decide to implement features that are antithetical to its users best interests, because there's a commercial imperative to do so. If the code is closed-source, it's more difficult to assess whether this is the case.
- andrepd 6y agoWait a minute. So it's better to have government finances be closed to the public, right? Because after all, you would need to audit 100,000s of pages of documents to understand what's going on -- which isn't feasible for anyone.