|
|
|
|
|
by kasey_junk
3156 days ago
|
|
I think that might be where we disagree. Without a competent security audit I think you are falling back to trust. Open Source vs Closed source is not where I or the security professionals I know put most trust emphasis. I would enthusiastically trust something closed from Google over a rando open source project. But back to the original point, even the most basic audit steps are the same on an open source project vs closed one. Observe what the binary does & inspect it for standard patterns. |
|
I think having a trusted compiler is an important first step to trusting software, even if you have to analyize it in depth yourself.