3 ms·
Most people never review source code, and they certainly don't disassemble and review all the binaries. 'Many eyes' is a security fallacy in cases like this.
by anonyfuss 13y ago
Most people never review source code, and they certainly don't disassemble and review all the binaries. 'Many eyes' is a security fallacy in cases like this.
- steveklabnik 13y agoTails is ridiculously well known; if something was bad in it, it would be big news.
- mseebach 13y agoIf it was found. Which is the point. Debian, which is much better known and in much wider circulation than Tails generated weak SSH keys for two years. Yes, it was indeed very big news. When it was found. After two years. Oh, and tin-foil-hat on: Do we know (actually know-know, not just assume, think, trust) that the weakness wasn't planted there?
- deleted 13y ago[deleted]
- EvilLook 13y agoTAILS is actually now done by the Tor Project, so I think they have a vested interest in vetting it before it is released. https://www.torproject.org/projects/projects/ https://www.torproject.org/projects/projects/
- mseebach 13y agoAnd Debian doesn't have a vested interest in making sure a central security component isn't weakened? Also, how do you know that Tor and Tails aren't infiltrated by the enemy (for any value of "enemy")?