Hacker News new | ask | show | jobs
by gwu78 4581 days ago
Surprise. Another purportedly "secure" application where the developers are not releasing the full sourse code.

I just don't understand what the theory is behind a closed source application that purports to be "secure". This is a very bold claim to make. How does the educated user decide whether she wants to trust the developers? She is not permitted to see their work.

Maybe there is something to be said for putting your code out in the open and letting everyone see what you've done. Letting others review your code and submit fixes (e.g. for platform specific issues). And then having numerous very determined people try to find serious flaws, and fail to find any.

Then again, maybe not. But one thing is for sure: Closed source does not allow that vetting process to happen.

1 comments

I don't disagree with your points at all, but for what it is worth, they say they will be opening the source "Soon"[1] and have started populating a Github account[2].

1. https://getsyme.com/faq

2. https://github.com/symeapp

Yes, I didn't mention it, but I have seen this before as well (other projects aimed at secure communications who "launch" but "delay" the release of the source code); I find this "delayed/promised open source" tactic equally perplexing. If they later release the source code, but users are already blindly routing their sensitive information through the system (because they launched first, before releasing the code), then it's too late for those users if it is later found the software is not trustworthy.