Hacker News new | ask | show | jobs
by maqp 2127 days ago
If you have your closed-source app audited, everyone needs to trust the audit company. And I've seen some shit audits in my life that told absolutely nothing about the actual security.

Open source means anyone can audit and verify nothing was done after audit.

Moxie more or less audited WhatsApp's Signal protocol implementation, and people are right to be concerned about whether changes have been made since FB bought the app.

1 comments

It can also be reverse engineered by third parties. Whatsapp in particular has been subject to extensive analysis by reverse engineering.