3 ms·
It is very much related: closed source software isn't audited in the open. Core principle of building secure software is one must assume that their adversary ha
by strlen 13y ago
It is very much related: closed source software isn't audited in the open. Core principle of building secure software is one must assume that their adversary has the source code and is actively building newer and newer attacks based on it (corporate leaks happen all the time). It's not impossible to follow through with this principle when building closed source software, but it is a lot easier to handwave it.
I am not a fan of FSF's tone here, they could be more diplomatic -- but saying "we appreciate your effort, but you fail" would have been more insulting. I think there are many places for closed source software, but core privacy software is not one of those places.
The encryption core (the critical pieces that either input or output plain text -- the places where the attack is more likely to succeed as opposed to the core of the algorithms), as well and the general platform should have the source code available (even if at a fee). That's not quite the FSF vision, but perhaps the powerful vision is needed (one can think of FSF's goals as a captivating utopian story that leads to more incremental improvements).