5 ms·
Would a 3rd party audit work? https://mullvad.net/en/blog/2021/1/20/no-pii-or-privacy-leaks-found-cure53s-infrastructure-audit/ https://mullvad.net/en/blog/202
by slavak 4y ago
Would a 3rd party audit work?
https://mullvad.net/en/blog/2021/1/20/no-pii-or-privacy-leaks-found-cure53s-infrastructure-audit/ https://mullvad.net/en/blog/2021/1/20/no-pii-or-privacy-leak...
- SV_BubbleTime 4y agoThat’s very good. But what do I know about “Cure53” other than they are saying “Yea, trust them bro”. Is Cure53 incorruptible? Would there be any blip in the world if they were not and Mull was really an NSA op? I’m not saying I don’t trust Mull over say, Nord. I am saying the nature of the whole thing is non-falsifiable with our existing technologies. We can only determine who was lying by looking back after an incident, and most are kept secret.
- Foxboron 4y agocure53 has an impeccable reputation and delivered some of the best security analysis there is. Most of them are also public and on github. https://github.com/cure53/Publications https://github.com/cure53/Publications
- lillecarl 4y agoSo far their track record seems good enough. I mean if you have NSA on your threat model you'll have to take this into account... But most don't.
- ranger_danger 4y agoaudits are only valid for that one instant in time when it was performed. anything could have changed after the fact.
- Gigachad 4y agoYou could say the same about all auditing. A restaurant could have changed its food hygiene standards since it was audited. But a company with a history of periodic and successful audits is certainly a good trust marker for me.
- ranger_danger 4y agoRestaurants routinely can't uphold their standards and often get wildly different results on every inspection. But yes I do say the same about all audits.