Join Nostr
2025-12-02 21:46:46 CET
in reply to

npub1c3…w4dgp on Nostr: It's correct that open source doesn't guarantee that all vulnerabilities are found. ...

It's correct that open source doesn't guarantee that all vulnerabilities are found.
But OSS can be reviewed by anybody at anytime, the developers cannot control by whom.
Closed source is sometimes also reviewed. But who prevents closed source developers of removing backdoor code just before a review and add it immediately afterwards again? Who selects the reviewers? It's all in the hands of the closed source manufacturer.
So how can anyone trust closed source?