13 ms·
Nope. Not trust, because they are open source and I can read the source code and I do read source code. Although this is kinda derailing my argument. I am sayin
by f4stjack 14y ago
Nope. Not trust, because they are open source and I can read the source code and I do read source code. Although this is kinda derailing my argument. I am saying, they don't have my data - not voluntarily if I accept your argumentation and assume they are collecting it without my consent, if this is the case; this will open a can of worms.
- pilif 14y agoUnless you compile the whole distro and all updates on your own, you still have to trust Ubuntu that the code they ship was actually built from source packages unmodified from the one you just checked. So you do have to trust them. They could easily have shipped a version of Chrome that sends the browsing history (or your password keychain) to Canonical while shipping source code that doesn't contain that feature. Of course this doesn't change the fact that I really do want my OS ad-free. It does mean however that I trust them not to violate their promises as well as not to ship spyware. If it gets out that they did either, it's the moment that everybody stops using Ubuntu which really doesn't help them in their (apparently perceived evil) monetization schemes.
- takluyver 14y agoThat's not just trust in them, it's partly trust in the community that if they shipped a malicious browser, say, someone would notice and cry foul. Offering source that doesn't match the binaries doesn't stop someone monitoring their own network traffic. And if you recompile the binaries with the same settings, the hashes should match.