Hacker News new | ask | show | jobs
by buu700 1270 days ago
Source code is necessary for trust, but not sufficient.
1 comments

It's a nice data point, but it's not necessary to me. Do you have the source code to your mail service provider or your online banking software? [1]

Having the source code available says a few nice things:

1. This company is confident enough to show their work

2. This company is "good" at software engineering (or it could reveal the opposite)

[1] I know some people can and do run their own mail servers. I can respect that, but I trust the Google devs and organization to be properly competent and incentivized to do a good job keeping my email account safe.

My mail provider and bank may be fine for their intended purposes, but I definitely don't trust them for storage of secrets or keys.