4 ms·
I want "security" software authors to stop doing harm. Just as physicians take up the Hippocratic Oath, I think we need to set higher standards for programs, ap
by forward1 3y ago
I want "security" software authors to stop doing harm. Just as physicians take up the Hippocratic Oath, I think we need to set higher standards for programs, applications and processes which avow to improve security, because too often they seem to have the opposite effect. Traditional anti-virus tools are a classic example of this.
I do see their website now, but I'm still confused:
> We are a team of visioneers, engineers, designers, and security experts backed by top-tier VCs who believe in making security work for everyone.
Great. What makes you security experts? In other words, why should we trust you?
You say the code is open source and that makes it trustworthy, but source availability is not a panacea. It must really be vigorously stressed, tested and abused by competent hackers (as a consensual contracted service) - again, if we are to call it "security" software.
Plainly, this is a beta test for a company that wants to make some money and has generously externalized bugs, issues and other nuances of development unto the open source community, which through some sort of Stockholm Syndrome has actually convinced itself more code - even if it's not good code - is still a good thing.
- insanitybit 3y agoThis is such a ridiculous sentiment. You're blaming these people for Antivirus now? Your whole post is just a nonsensical rant. If you want to say "I'd like to see software like this audited for security" just say so.
- jasonjayr 3y agoThen there's the followup question: Who trusts the auditors?
- idkyall 3y agoWell - since it's open source, theoretically you can build it yourself and "trust but verify" the audit, although there we're also assuming you trust your own judgement or that of your security team.
- jasonjayr 3y agoWell, right, of course. My comment is more along the lines of "paying for an audit implies putting faith in those auditors to do a good enough job"
- xyst 3y agoIt’s open source. I’ll inspect the source myself. Cross check against auditor findings. Build from source
- mrits 3y agoConsider this a medical trial