Hacker News new | past | comments | ask | show | jobs | submit login

I might get bashed for this but open source isn't secure at all. Have we had a month where no heavily used dependency gets infected?

Proprietary code that's been audited is already better then most projects

Not sure why phone number matters. Pretty much anyone can find your phone number




>Proprietary code that's been audited is already better then most projects

Even better would be open source code that's been 3rd-party audited. Because you have formal audits, plus several informal audits. Like Signal.


Here is the problem...is Open Source less secure because people find more software bugs, or is that accomplishing the whole purpose of open source technology? With the source code public, people find more bugs and it comes across as less secure, but they ultimately get fixed. A lot of those same bugs go unnoticed for years in proprietary software, and as a result its less secure. Yeah, proprietary software can be audited, but you only have like one or two guys doing the audit. They are going to miss something big. More eyes is better than few eyes.

As far as the phone number goes, the person above is more focused on anonymity than anything else. You having your phone number tied to it is a pretty big cause of concern if that is the goal you are after unless you use a throwaway number.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: