Hacker News new | ask | show | jobs
by maqp 2129 days ago
Nobody's claimed that. Open source is not panacea for verifiable security, it is however a requirement of it.
1 comments

No, it is not necessary _or_ sufficient. That is what I'm saying. You can audit a closed-source app, and there also might be open-source apps which are impractical to audit despite them being open source.
If you have your closed-source app audited, everyone needs to trust the audit company. And I've seen some shit audits in my life that told absolutely nothing about the actual security.

Open source means anyone can audit and verify nothing was done after audit.

Moxie more or less audited WhatsApp's Signal protocol implementation, and people are right to be concerned about whether changes have been made since FB bought the app.

It can also be reverse engineered by third parties. Whatsapp in particular has been subject to extensive analysis by reverse engineering.