4 ms·
A "snoop free alternative" demands a transparent implementation that can be verified. Otherwise, how can we trust the claims of being "snoop free"? The extent
by mvanveen 13y ago
A "snoop free alternative" demands a transparent implementation that can be verified. Otherwise, how can we trust the claims of being "snoop free"?
The extent that we can verify a system is the extent to which we can trust it.
This makes me think that free/open source software solutions are going to become an integral piece of whatever solution such companies are attempting to offer.
Going a bit further on the idea of verification, I'm curious why there aren't any organizations or companies I'm aware of which are dedicated to providing this sort of verification of open source systems out in the wild. Is it just that most of the talent for this capability is sequestered into the infosec consulting market, for example, or does it have to do with the difficulty of actually verifying said systems? Are all of these entities instead focusing on the offensive and just selling off 0day exploits?
- avifreedman 13y agoFinding the problems with FOSS (or really any body of closed or open source or object code) usually requires at least challenging assumptions (not "oh yeah I sort of see what's going on" but digging in) or real creativity. The thing that seems to drive that is profit or geek-respect motive, so the folks doing said verification would need to be probably not your average bear doing a job or even person pretty interested but multitasking. I think it'd be hard to find and manage such a work and/or volunteer force at scale well enough to really think that a creative and hard-core security review had been accomplished.