4 ms·
Open code, inspected and used by a large number of users, hosted on hardware you physically control
by ENGNR 2y ago
Open code, inspected and used by a large number of users, hosted on hardware you physically control
- ryr11 2y agoI think that's fair, but impractical for most users. I have a number of Home Assistant integrations with locally hosted AI models for smart home features, but I wouldn't expect my grandma to set up a server and a few VMs when she could just give her HomePod a prompt that works with AI and have no worries about the implementation. Do you feel like Apple's "independent" auditing is insufficient?
- ENGNR 2y ago> Do you feel like Apple's "independent" auditing is insufficient? Yeah, pretty much Also, your grandma might not setup a VM, but it sounds like the off-device processing is essentially stateless, or at most might have a very lightweight session. It seems like the kind of thing one person could setup for their family (with the same tamper-proof signatures, plus physical security), or provide a privacy focused appliance for anyone to just plug into a wall, if they wanted to.
- threeseed 2y agoMost open source code isn't inspected though. There have been many cases recently of compromised code being in the wild for quite some time and then only known about by accident.
- spywaregorilla 2y ago100% of closed code is not inspected
- sodality2 2y agoBy you. Three comments above references "independent audits". Meaning professional cybersecurity firms
- jeroenhd 2y agoFrom. what I can tell, Apple doesn't actually provide the source code itself, or provides the (cryptographically verified) binaries and VMs to run it. Reverse engineering will still need to take place, it seems.
- theshrike79 2y agoI have been involved in security audits for 110% closed code, code that's secret even within the company. Auditing helps the company writing it, the auditors are usually experts in breaking stuff in fun ways, and it's good for business - we could slap "code security audited by XXX" on the sales pitch.
- spywaregorilla 2y ago> and it's good for business - we could slap "code security audited by XXX" on the sales pitch. You're on the precipice of discovering the problem of incentives when it comes to audits. Audits are good, but they're inferior to source available