Comment on ICEBlock - See Something, Tap Something

<- View Parent
cubism_pitta@lemmy.world ⁨1⁩ ⁨day⁩ ago

When you do business with companies in certain industries not only is your software audited but your entire development process, business processes and staff are audited.

It’s not unreasonable to question a closed source application for something like this as one version was audited, but what about the next?

How do we know their dev process hasn’t been compromised? Or the person building app wasn’t compromised? Or that the entire thing was not compromised from the start?

Likewise, an audit without full access to code isn’t useless, but hiding behavior from an audit and for a certain period of time would be straight forward. How do you know there is not a dormant command and control system in the app that will cause it to behave in a malicious manner after a set amount of time or after a specific push notification is received?

I am not saying this is present, just that Audits like this are only able to catch what they can observe and the existence of an audit does not mean to blindly trust something

Having the App be open source would be a big step towards providing the transparency needed to address these concerns users would not have to trust anyone and can confirm the builds on the app stores match what is on their Git.

I am not pointing this out to jump on the “Don’t use this app” bandwagon. I am pointing it out to say that there are reasons to be skeptical of these sorts of things in our current political climate.

Remember Sabu and LulzSec

source
Sort:hotnewtop