Hacker News new | ask | show | jobs
by gjsman-1000 1186 days ago
Never forget though, Auditing is only proof that it was secure at the moment of the audit. That applies to all VPNs and services.
3 comments

Rather, auditing is only proof that the parts the auditors looked at were secure against what the the auditors knew to look for, at the moment of the audit.
Auditing might not even cover the entire codebase.

For example, this is the writeup of the DeFi Euler hack yesterday by one of the sites listed auditors, who didn't actually audit the code that caused the bug...

https://medium.com/@omniscia.io/euler-finance-incident-post-...

That's true. Good point.