3 ms·
It's funny that you think proprietary code is audited.
by guappa 1y ago
It's funny that you think proprietary code is audited.
- amelius 1y agoWell, I suppose there is a tighter control on who is allowed to commit.
- GTP 1y agoYes, but you have less people that can look at such commits. It's not so easy to claim that one is intrinsically more secure than the other. As someone in the cybersecurity field, I prefer FOSS software. But the situation is more nuanced than how you present it.
- guappa 1y agoNo there isn't. In fact proprietary projects are very happy to run "npm" or "pip install" or the java/go equivalents and install whatever. I expect most projects don't even check they're not violating licenses or ever audit any dependency… let alone do a security check on who the authors are. Also just FYI, russians are not stupid. If they want to contribute malware they won't do it from their kgb email address. They will create a fake identity with a very standard WASP name.
- amelius 1y agoI don't think that's true. Accountability will give proprietary projects an extra edge in terms of security.