|
|
|
|
|
by axelthegerman
920 days ago
|
|
Yes that's fair, however that's how our complex world works. E.g. we rely on journalism (the real kind) to uncover all kind of scummy behavior. Similar in the OSS world. There is no way to easily verify that unless some trusted bodies do this for us and publish their work specifically for what you're using. Now you just have been stating a problem and no solution. I do agree with you though that "hey it's OSS and easy to verify because we have the code" is indeed lying to ourselves and especially tools with privileges like this (MITM your encrypted traffic) should not be taken that lightly and have the proper warnings, disclaimer and attention (to watch for bad behavior) |
|