3 ms·
It's turtles all the way down. Would you rather NOT have the option for other experts to see the code?
by FatActor 4y ago
It's turtles all the way down. Would you rather NOT have the option for other experts to see the code?
- danShumway 4y agoOf course not, I'd rather the code be Open and audited. Being Open Source is in some ways a multiplier on security because it allows more expert review. But the expert review is the important part; if security-critical code is Open Source but hasn't been looked at by anyone other than the main developers, the Open Source part is a multiplier on zero. It's a little bit more complicated than that, and there are a lot other factors at play as well even outside of security. We're not really getting into stuff like future-proofing and what happens if 1Password gets a lot worse in the future. It's complicated. But the gist is that while it would be a lot better if 1Password was Open Source, it's still in its current state probably got more eyes on it than some Open Source security projects do.
- JamesBarney 4y agoWhen the tool is opened sourced honest and rogue security experts are going to go through it. Now how much value is the first adding versus the second removing is the case. And based on incentives for each, an honest security research maybe getting a small bug bounty, and a rogue one potentially gaining access to 10's of thousands of accounts I think it might be a net negative overall.