|
|
|
|
|
by munchbunny
1753 days ago
|
|
That's an overly cynical way of looking at this. Security audits of your code are a matter of course best practice and are unrelated to "does the VPN live up to its marketing claims?" It's like publishing that you passed health and safety inspection for a factory that makes safes. I don't think anyone would reasonably confuse a company publishing that its factory passed inspection for a claim that its safes are hard to break into. They released the full report here and it's pretty clear on what they did and didn't audit: https://blog.mozilla.org/security/files/2021/08/FVP-02-repor... |
|
(I know plutonium is not a good choice for the comparison as in the VPN case, we don't know if what will replace the script will be secure or not whereas plutonium is known to be unsafe, but the idea remains that changing something critical to safety after the audit is not nice to hear at all.)