Comment on Do you actually audit open source projects you download?

Vanth@reddthat.com ⁨1⁩ ⁨week⁩ ago

I don’t because I don’t have the necessary depth of skill.

But I don’t say I “blindly” trust anyone who says they’re FOSS. I read reviews, I do what I can to understand who is behind the project. I try to use software (FOSS or otherwise) in a way that minimizes impact to my system as a whole if something goes south. While I can’t audit code meaningfully, I can setup unique credentials for everything and use good network management practices and other things to create firebreaks.

source
Sort:hotnewtop