5 ms·
? Why?
by sauercrowd 3y ago
?
Why?
- INTPenis 3y agoI'm not the person you replied to but I agree, because it's related to public safety. Same with aviation software. Anything that deals with public safety should be audited by the public.
- thaumasiotes 3y agoMaybe we could start with this much less general principle: Whenever the output of software is offered as evidence against you in court, you should be entitled to the source code of the software.
- calgoo 3y agoThe post office workers in the UK who where f-ed over by the government because the software was reporting things incorrectly could really have used this as well. Should all our financial systems be open source too? Maybe it should be like Copyright or patents, you can keep things private for a while for an advantage, but then you would need to release all code as open source / public domain or similar? It should also be available before that to be reviewed by professionals following a formal process of some sort.
- adh636 3y ago> Should all our financial systems be open source too? Yes.
- jacquesm 3y agoThat's really a good thing you are on to there.
- thaumasiotes 3y agoMore downvotes than upvotes. :/
- jacquesm 3y agoHN doesn't like calls to take responsibility for what we produce. Regulation and responsibility are anathema here. But no worries, the world is fortunately a lot larger than that and little by little the tide seems to be turning towards holding the producers of software accountable for the works they produce, just like every other engineering discipline. I can't wait.
- mratsim 3y agoIt should be audited by professionals, but available for public reviews / additional audits. General folks and even most devs do not have the skills to audit code.
- INTPenis 3y agoNothing prevents the owner of the code to audit it themselves, but everyone else should also be able to. I think if you release code related to important everyday things like cars, everyone who is able will want to take a look. And you never know who will think outside the box and stumble across something they can then escalate and investigate with other people who are more capable. It happens in open source all the time.
- mratsim 3y agoAuditing your own code doesn't help if you have a blindspot. You will miss it while developing and auditing. > Everyone who is able will want to take a look. This is not true. Auditing is very skill intensive and time intensive. There needs to be compensation for it either direct (you pay for professional auditors) or indirect (you're an academic and you get reputation and grants for breaking WPA3, SGX, Mega or SIKE, or fame for breaking the PS3). You can easily get in a situation with "The Emperor has no clothes" where everyone thought open-source code must have been audited by someone because it's open, when in fact no one did because they didn't care or had no incentives.
- realusername 3y agoWe live now in a world where the most qualified people are explicitly not part of the old definition of "qualified professionals"
- mratsim 3y agoWhat do you mean?
- realusername 3y ago
- deleted 3y ago[deleted]