Hacker News new | ask | show | jobs
by martingxx 2636 days ago
There are plenty of companies who have released their source code but don't support it in the same way a typical community driven project like other open source projects do.

This is especially true for certain privacy and security focused applications. For example, Signal release their code, have quite a lot of users, and don't report an unmanageable overhead due to having released their source code.

It's not just a matter of trusting their intentions, it's a matter of knowing that their code matches their intentions. I trust OpenSSL (mostly, these days) and I always trusted the intentions of the developers, but if their code was not open it would not be half as secure today.