Hacker News new | ask | show | jobs
by slavak 1458 days ago
Would a 3rd party audit work?

https://mullvad.net/en/blog/2021/1/20/no-pii-or-privacy-leak...

2 comments

That’s very good. But what do I know about “Cure53” other than they are saying “Yea, trust them bro”.

Is Cure53 incorruptible? Would there be any blip in the world if they were not and Mull was really an NSA op?

I’m not saying I don’t trust Mull over say, Nord. I am saying the nature of the whole thing is non-falsifiable with our existing technologies. We can only determine who was lying by looking back after an incident, and most are kept secret.

So far their track record seems good enough. I mean if you have NSA on your threat model you'll have to take this into account... But most don't.
cure53 has an impeccable reputation and delivered some of the best security analysis there is.

Most of them are also public and on github.

https://github.com/cure53/Publications

audits are only valid for that one instant in time when it was performed. anything could have changed after the fact.
You could say the same about all auditing. A restaurant could have changed its food hygiene standards since it was audited. But a company with a history of periodic and successful audits is certainly a good trust marker for me.
Restaurants routinely can't uphold their standards and often get wildly different results on every inspection. But yes I do say the same about all audits.